Cisco confirms Secure FMC flaw under active attack
Cisco's 9 September 2026 advisory update (rev 2.5) says PSIRT saw active exploitation in August of CVE-2026-20079, a CVSS 10.0 Secure FMC auth bypass first published 4 March. CISA put it on KEV with a 12 September federal due date. Hot fixes cover FMC 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0.

Cisco's security advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2, first published 4 March 2026 and last updated 9 September 2026 as revision 2.5, now says Cisco PSIRT became aware of active exploitation in August 2026. The advisory covers an authentication bypass in Cisco Secure Firewall Management Center software, tracked as CVE-2026-20079, CVSS base 10.0, bug CSCwr96008. This is an updated advisory confirming exploitation, not a new zero-day disclosed today.
An unauthenticated remote attacker can bypass authentication on the Secure FMC web interface and execute scripts that yield root on the operating system. Cisco says the root cause is an improper system process created at boot time, reached with crafted HTTP requests. The flaw affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management regardless of device configuration. SCC SaaS is already fixed by Cisco, so customers there have no action.
Cisco confirms Firewall Device Manager, ASA Software, FTD Software, and SCC (formerly Defense Orchestrator) are not vulnerable. There are no workarounds. Keeping the management interface off the public internet reduces the attack surface.
Hot fixes are posted for FMC 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Cisco says those packages prevent future exploitation and may not remediate an existing compromise. The advisory's indicator is an expert-mode zgrep for package_info.*license that shows a /var/tmp/license.tmp path. If that line appears, open a TAC case.
SecurityWeek reports CISA added CVE-2026-20079 to the Known Exploited Vulnerabilities catalog with a federal due date of 12 September. That is the third FMC CVE on KEV in 2026, after CVE-2026-20316 and CVE-2026-20131.
SecurityWeek, summarizing Cisco Talos, describes three clusters on CVE-2026-20079 and/or CVE-2026-20316: UAT-12197 (webshell plus a malicious JAR and credential theft), UAT-11823 tied to Sandworm delivering Cyclops Blink, and UAT-11988 tied to Qilin ransomware on CVE-2026-20316. Those actor labels sit in the SecurityWeek write-up of Talos, not in the Cisco advisory body.
The same internet-facing management-plane pattern shows up in SonicWall SMA 1000, Microsoft's September Patch Tuesday, F5 BIG-IP memory webshells, and JFrog Artifactory's auth bypass.
If you run on-prem Secure FMC, apply the matching 7.0, 7.2, 7.4, 7.6, 7.7, or 10.0 hot fix before the 12 September KEV deadline, pull management interfaces off the public internet, and open a TAC case immediately if the license.tmp indicator appears in messages logs.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free