Cisco Confirms Active Exploitation of Critical Secure FMC Vulnerability
Share
Cisco has confirmed that a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.
The vulnerability, tracked as CVE-2026-20079, carries a CVSS score of 10.0. It allows unauthenticated, remote attackers to bypass authentication mechanisms and execute scripts and commands with root privileges on affected devices.
Technical Details and Exploitation
The flaw stems from an improper system process created during the boot sequence. Attackers can exploit this vulnerability by sending specially crafted HTTP requests to the web interface of an affected device.
While Cisco’s Product Security Incident Response Team (PSIRT) stated it became aware of the active exploitation in August 2026, evidence suggests the flaw may have been targeted earlier. Indicators of compromise (IOCs) identified in late July suggest that exploitation could have been occurring weeks before the official confirmation of active attacks.
Regulatory Response and CISA Action
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalogue. As a result, CISA has ordered all Federal Civilian Executive Branch agencies to secure their vulnerable systems by 12 September 2026.
Affected Systems and Remediation
The vulnerability impacts the following products:
- Cisco Secure FMC Software
- Cisco Security Cloud Control Firewall Management
Cisco has already implemented patches for its cloud-hosted Security Cloud Control service. For on-premise software, there are currently no known workarounds, and the company strongly recommends that customers upgrade to the latest software release immediately.
Cisco has cautioned that while installing the available hotfixes will prevent future exploitation, the updates will not remediate devices that have already been compromised by attackers. Administrators who discover indicators of compromise—such as log entries in /var/log/messages involving /var/tmp/license.tmp—are advised to contact the Cisco Technical Assistance Center (TAC) for support.




Leave a Reply