Download Privacy Needle App

Type to search

Cybersecurity

Cisco Confirms Active Exploitation of Critical Secure FMC Vulnerability

Share

Cisco has confirmed that a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.

The vulnerability, tracked as CVE-2026-20079, carries a CVSS score of 10.0. It allows unauthenticated, remote attackers to bypass authentication mechanisms and execute scripts and commands with root privileges on affected devices.

Technical Details and Exploitation

The flaw stems from an improper system process created during the boot sequence. Attackers can exploit this vulnerability by sending specially crafted HTTP requests to the web interface of an affected device.

While Cisco’s Product Security Incident Response Team (PSIRT) stated it became aware of the active exploitation in August 2026, evidence suggests the flaw may have been targeted earlier. Indicators of compromise (IOCs) identified in late July suggest that exploitation could have been occurring weeks before the official confirmation of active attacks.

Regulatory Response and CISA Action

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalogue. As a result, CISA has ordered all Federal Civilian Executive Branch agencies to secure their vulnerable systems by 12 September 2026.

Affected Systems and Remediation

The vulnerability impacts the following products:

  • Cisco Secure FMC Software
  • Cisco Security Cloud Control Firewall Management

Cisco has already implemented patches for its cloud-hosted Security Cloud Control service. For on-premise software, there are currently no known workarounds, and the company strongly recommends that customers upgrade to the latest software release immediately.

Cisco has cautioned that while installing the available hotfixes will prevent future exploitation, the updates will not remediate devices that have already been compromised by attackers. Administrators who discover indicators of compromise—such as log entries in /var/log/messages involving /var/tmp/license.tmp—are advised to contact the Cisco Technical Assistance Center (TAC) for support.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.