Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » CVE-2026-20079 Actively Exploited, CISA Orders Federal Patch by September
    Technology

    CVE-2026-20079 Actively Exploited, CISA Orders Federal Patch by September

    Gary BehanBy Gary Behan17/09/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    CVE-2026-20079 actively exploited
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    Cisco has confirmed that CVE-2026-20079 is actively exploited in the wild, a maximum-severity authentication bypass flaw in its Secure Firewall Management Center (FMC) software carrying a CVSS score of 10.0. The admission, quiet as it was, matters: Cisco first disclosed the vulnerability in March and said at the time it had no evidence of exploitation.

    The flaw allows unauthenticated, remote attackers to bypass authentication entirely and execute scripts and commands as root on vulnerable devices. It is caused by an improper system process created at boot time, and can be triggered by sending crafted HTTP requests to the web interface of an affected device. No credentials required. No workaround available.

    ‘In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability,’ Cisco stated in an updated advisory on Wednesday. The company did not disclose when the attacks began, who was behind them, or what post-exploitation activity was observed.

    CVE-2026-20079 Actively Exploited: The Timeline Does Not Start in August

    Here is where things get uncomfortable for that August framing. Indicators of compromise (IOCs) published in a July advisory update suggest the flaw may have been exploited considerably earlier. On 29 July, Cisco disclosed a separate Secure FMC vulnerability, CVE-2026-20316, caused by static credentials for a low-privileged account, and confirmed it had been actively exploited. Cisco assigned it a High severity rating, noting that the access could be combined with other FMC vulnerabilities to elevate privileges.

    At the same time, as BleepingComputer reported, Cisco quietly updated the CVE-2026-20079 advisory to include the same IOCs as CVE-2026-20316, without confirming exploitation of the authentication bypass flaw. Cisco told administrators to search /var/log/messages for activity related to /var/tmp/license.tmp, and shared an example log entry dated 23 July: several weeks before Cisco says PSIRT became aware of exploitation in August.

    BleepingComputer contacted Cisco to ask whether the two vulnerabilities were connected, whether CVE-2026-20079 had also been exploited, and whether the shared indicator had been added intentionally. Cisco did not answer those questions directly. ‘On July 29, 2026, Cisco released software fixes to address vulnerabilities in Cisco Secure Firewall Management Center,’ a Cisco spokesperson told BleepingComputer. ‘Cisco strongly recommends customers immediately apply the available fixes.’

    Cisco’s latest update now confirms exploitation of CVE-2026-20079 but stops short of clarifying whether the 23 July log activity reflects exploitation of one vulnerability or both. The overlap is hard to ignore: the same IOCs, identical July hot fixes, and a log entry predating Cisco’s stated August awareness all point toward the possibility that both flaws were used in the same attacks.

    CISA Adds the Flaw to Its Known Exploited Vulnerabilities Catalogue

    The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalogue, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by 12 September 2026. The vulnerability affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management. Cisco says it has already patched the cloud-hosted Security Cloud Control service, but on-premises deployments require a software upgrade.

    Cisco advises customers who discover the indicators of compromise to contact its Technical Assistance Centre (TAC) for support. Critically, the company warns that installing the hot fixes will prevent future exploitation but will not remediate devices that are already compromised. If an attacker has been and gone, the hot fix is not a clean-up tool.

    The FMC product line has been under sustained pressure. According to Acronis, researchers reported that Interlock ransomware exploited a separate Cisco Secure Firewall Management Center vulnerability, CVE-2026-20131, beginning in late January, a reminder that threat actors have been probing this attack surface for months and that patching FMC deployments is not a matter of routine hygiene, it is an active incident-response priority.

    Customers are advised to upgrade to the latest software release immediately. For those who find the 23 July log entry in their systems, Cisco says the vulnerability ‘may have been exploited’ and recommends contacting TAC without delay.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleCISA Advisory AA26-251A: Chinese AI Distillation Attacks Drained Billions of Tokens from US Models
    Next Article WatchGuard Firebox Ransomware Attacks Confirmed as CISA Updates KEV Catalogue
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    KB5124008 patches Windows 11 mouse settings reset caused by August update

    17/09/2026

    WatchGuard Firebox Ransomware Attacks Confirmed as CISA Updates KEV Catalogue

    17/09/2026

    CISA Advisory AA26-251A: Chinese AI Distillation Attacks Drained Billions of Tokens from US Models

    16/09/2026

    Veradigm Patient Data Breach Tied to Vendor API Credentials Stolen by Ransomware Gang

    16/09/2026

    Plex Media Server unpatched flaws leave 36,000 servers exposed online

    16/09/2026

    Microsoft September 2026 Patch Tuesday Breaks Records With 966 Flaws and Two Zero-Days

    15/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.