Cisco confirms maximum-severity FMC flaw is being actively exploited

A maximum-severity authentication bypass in Cisco's Secure Firewall Management Center (FMC) software is being actively exploited in the wild, Cisco confirmed on Wednesday — months after the vulnerability was first disclosed and patched in March.
The flaw, tracked as CVE-2026-20079 with a perfect CVSS score of 10.0, allows unauthenticated remote attackers to bypass authentication entirely and execute scripts and commands with root privileges on vulnerable devices. The bug stems from an improper process created at boot time; exploitation requires only crafted HTTP requests sent to the device's web interface.
CISA orders federal patch by September 12
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday and ordered all Federal Civilian Executive Branch agencies to secure vulnerable systems before September 12, 2026. Enterprise defenders should treat this deadline as the outer limit, not a target date.
Cisco's Product Security Incident Response Team said it became aware of active exploitation in August, but indicators of compromise published in a related July advisory suggest attacks may have begun as far back as July 23 — weeks earlier than the company acknowledged. Cisco told administrators to search /var/log/messages for activity referencing /var/tmp/license.tmp; the presence of that pattern means the device may have been compromised.
No workarounds — upgrade required
Cisco says there are no workarounds available. Admins must upgrade to the latest Secure FMC software release. The company has already patched its cloud-hosted Security Cloud Control service. Critically, installing the hot fix prevents future exploitation but does not remediate devices already compromised — organizations that find exploitation indicators should contact Cisco TAC immediately for incident response guidance.
CVE-2026-20079 is part of a cluster of related Secure FMC vulnerabilities. In July, Cisco also confirmed active exploitation of CVE-2026-20316, a separate flaw that exposed static credentials for a low-privileged account. Shared indicators of compromise across both advisories, plus identical July hot fix releases, suggest the two bugs were likely chained in the same attack campaigns.
As first reported by BleepingComputer, Cisco added the CVE-2026-20079 exploitation indicators to its advisory in late July but stopped short of confirming active exploitation at the time — a gap that left defenders without a clear signal for nearly six weeks.
Originally reported by BleepingComputer. Read the original article for additional details.
View original source