Cisco confirms vulnerability of CVE-2026-20079 Secure FMC used in attacks

Cisco

Cisco has confirmed that a maximum severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.

The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices.

“In August 2026, Cisco’s PSIRT became aware of active exploitation of this vulnerability,” Cisco updated CVE-2026-20079 advisory let me say on wednesday.

Cisco did not disclose when the attacks began, who was behind them, or what post-exploitation activity was observed.

Cisco first disclosed CVE-2026-20079 in March, when the company said there was no evidence the vulnerability was being exploited in attacks.

The vulnerability is caused by a malformed system process created at boot time and can be exploited by sending crafted HTTP requests to the affected device’s web interface.

A successful attack could allow an unauthorized attacker to execute scripts and commands on the rooted device.

The vulnerability affects Cisco Secure FMC software and Cisco Security Cloud Control Firewall Management. Cisco says it has already patched its cloud-hosted Security Cloud Control service.

Cisco says there are no workarounds and recommends customers upgrade to the latest software version.

Today, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its catalog of known exploited vulnerabilities (KEV), ordering federal civil enforcement agencies to secure vulnerable systems by September 12, 2026.

Evidence of exploitation emerged in July

While Cisco says its security team became aware of active use of CVE-2026-20079 in August, IOCs published in an advisory update from July suggest the flaw may have been exploited earlier.

On July 29. Cisco revealed another Secure FMC vulnerabilitytracked as CVE-2026-20316, caused by static credentials for a low-privilege account.

Cisco said at the time that CVE-2026-20316 was actively used in attacks and assigned it a high severity rating because access can be combined with other Secure FMC vulnerabilities to elevate privileges.

As BleepingComputer reported at the time, Cisco also updated the CVE-2026-20079 advisory to include the same indicators as CVE-2026-20316, but did not confirm that the flaw was exploited.

Cisco told administrators to look in /var/log/messages for activity related to /var/tmp/license.tmp and shared the following sample log entry:


Jul 23 16:16:33 firepower sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm

Cisco says that if this record is found, the vulnerability “may have been exploited” on the Secure FMC device under investigation.

The sample log entry is dated July 23, weeks before Cisco said PSIRT became aware of the CVE-2026-20079 exploit in August.

Cisco also released the same Secure FMC hotfixes for both CVE-2026-20316 and CVE-2026-20079.

At the time, BleepingComputer contacted Cisco to ask if the two vulnerabilities were related, if CVE-2026-20079 was also exploited, and if Cisco intentionally added the shared indicator to the two advisories.

Cisco did not directly answer the questions and instead shared the following statement:

“On July 29, 2026, Cisco released software patches to address vulnerabilities in the Cisco Secure Firewall Management Center (FMC). Details are described in the security advisories (Static Credentials Vulnerability, Authentication Bypass Vulnerability) and Cisco strongly recommends that customers apply the available patches immediately,” a Cisco spokesperson told BleepingComputer.

“Customers requiring support should contact the Cisco Technical Assistance Center (TAC).”

Cisco’s latest update now confirms that CVE-2026-20079 was exploited, but does not clarify whether the July 23 activity involved exploiting both vulnerabilities.

However, the same IOCs for both flaws, identical July hotfixes, and a July 23rd log entry suggest that both vulnerabilities may have been used in the same attacks.

Cisco advises customers who find indicators of compromise to contact its TAC for support, warning that installing the hotfixes will prevent future exploitation but will not fix already compromised devices.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *