Cisco FMC CVE-2026-20079 Actively Exploited
Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) with a maximum CVSS score of 10.0.
The flaw allows an unauthenticated remote attacker to execute scripts and commands with root privileges on affected devices. With attacks now observed in the wild, organizations running Secure FMC should apply Cisco’s fixes and investigate potentially exposed appliances for signs of prior compromise.
How Does CVE-2026-20079 Affect Cisco FMC?
CVE-2026-20079 affects the web interface of Cisco Secure FMC Software and stems from an improperly created system process at boot time.
An unauthenticated attacker with network access to the interface can send crafted HTTP requests to bypass authentication. Successful exploitation can allow scripts and commands to execute with root-level access to the underlying operating system.
Cisco notes that keeping the FMC management interface off the public internet reduces the attack surface, but this does not remediate the vulnerability.

Details of CVE-2026-20079 (SOCRadar Vulnerability Intelligence)
The vulnerability also affects Cisco Security Cloud Control (SCC) Firewall Management, regardless of configuration. Cisco has already deployed the fix to the SaaS-hosted SCC Firewall Management service, so no customer action is required for that service.
Cisco says Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software, and Security Cloud Control, formerly Defense Orchestrator, are not affected.
What Do We Know About Active Exploitation?
Cisco originally disclosed CVE-2026-20079 on March 4, 2026. On September 9, Cisco updated its advisory to say its Product Security Incident Response Team (PSIRT) became aware of active exploitation in August.
Cisco Talos has since detailed multiple intrusion clusters targeting Secure FMC. One cluster exploited CVE-2026-20079 and deployed web shells, a JAR-based command executor, and credential-stealing capabilities.
Another cluster combined CVE-2026-20079 with CVE-2026-20316, a separate Secure FMC vulnerability involving static credentials. That activity led to reverse shell and proxy deployment and ultimately a variant of Cyclops Blink malware. Talos associated the activity with clusters it tracks separately, while another FMC intrusion involving CVE-2026-20316 was linked to ransomware-related activity.
CISA also added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog on September 9, setting a September 12 remediation deadline for U.S. federal civilian agencies.
How Should Organizations Respond to CVE-2026-20079?
Cisco has released hot fixes for Secure FMC release branches 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Organizations should use the Cisco security advisory for CVE-2026-20079 to identify the appropriate hot fix or fixed software release for their deployment.
There is no workaround that fully addresses the vulnerability. Restricting management-interface access to trusted administrative networks can reduce exposure but does not replace patching.
Importantly, Cisco warns that its hot fixes prevent future exploitation but may not address an existing compromise. If indicators of compromise are present, Cisco recommends contacting its Technical Assistance Center (TAC) for recovery guidance.
![]()
SOCRadar’s Vulnerability Intelligence
SOCRadar’s Cyber Threat Intelligence module can help teams track CVE-2026-20079, exploitation developments, remediation status, and affected assets. Combined with Attack Surface Management (ASM), organizations can also identify unexpectedly exposed management interfaces that may require immediate attention.
Check Cisco’s Exploitation Indicator
Cisco provides a log-based indicator that administrators can use when investigating possible exploitation. The relevant activity involves the www service invoking package_info.pl against /var/tmp/license.tmp in system messages.
Cisco cautions that finding this activity indicates the vulnerability may have been exploited, rather than providing definitive proof of compromise. Security teams should preserve surrounding logs and investigate related administrative, process, network, and credential activity.
Cisco has also published Snort SIDs 66075–66080 for CVE-2026-20079.
What Should Defenders Prioritize?
Organizations operating Secure FMC should identify every affected instance, determine its software version and management-interface exposure, and apply the appropriate Cisco hot fix or fixed release.
Because exploitation is confirmed, teams should also review historical telemetry rather than treating successful patching as proof that an appliance was never compromised. Preserve evidence before remediation if suspicious activity is identified and investigate subsequent credential access, configuration changes, persistence, or connections into the wider environment.

