Cisco has confirmed that CVE-2026-20079 is actively exploited in the wild, a maximum-severity authentication bypass flaw in its Secure Firewall Management Center (FMC) software carrying a CVSS score of 10.0. The admission, quiet as it was, matters: Cisco first disclosed the vulnerability in March and said at the time it had no evidence of exploitation.

The flaw allows unauthenticated, remote attackers to bypass authentication entirely and execute scripts and commands as root on vulnerable devices. It is caused by an improper system process created at boot time, and can be triggered by sending crafted HTTP requests to the web interface of an affected device. No credentials required. No workaround available.

‘In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability,’ Cisco stated in an updated advisory on Wednesday. The company did not disclose when the attacks began, who was behind them, or what post-exploitation activity was observed.

CVE-2026-20079 Actively Exploited: The Timeline Does Not Start in August

Here is where things get uncomfortable for that August framing. Indicators of compromise (IOCs) published in a July advisory update suggest the flaw may have been exploited considerably earlier. On 29 July, Cisco disclosed a separate Secure FMC vulnerability, CVE-2026-20316, caused by static credentials for a low-privileged account, and confirmed it had been actively exploited. Cisco assigned it a High severity rating, noting that the access could be combined with other FMC vulnerabilities to elevate privileges.

At the same time, as BleepingComputer reported, Cisco quietly updated the CVE-2026-20079 advisory to include the same IOCs as CVE-2026-20316, without confirming exploitation of the authentication bypass flaw. Cisco told administrators to search /var/log/messages for activity related to /var/tmp/license.tmp, and shared an example log entry dated 23 July: several weeks before Cisco says PSIRT became aware of exploitation in August.

BleepingComputer contacted Cisco to ask whether the two vulnerabilities were connected, whether CVE-2026-20079 had also been exploited, and whether the shared indicator had been added intentionally. Cisco did not answer those questions directly. ‘On July 29, 2026, Cisco released software fixes to address vulnerabilities in Cisco Secure Firewall Management Center,’ a Cisco spokesperson told BleepingComputer. ‘Cisco strongly recommends customers immediately apply the available fixes.’

Cisco’s latest update now confirms exploitation of CVE-2026-20079 but stops short of clarifying whether the 23 July log activity reflects exploitation of one vulnerability or both. The overlap is hard to ignore: the same IOCs, identical July hot fixes, and a log entry predating Cisco’s stated August awareness all point toward the possibility that both flaws were used in the same attacks.

CISA Adds the Flaw to Its Known Exploited Vulnerabilities Catalogue

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalogue, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by 12 September 2026. The vulnerability affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management. Cisco says it has already patched the cloud-hosted Security Cloud Control service, but on-premises deployments require a software upgrade.

Cisco advises customers who discover the indicators of compromise to contact its Technical Assistance Centre (TAC) for support. Critically, the company warns that installing the hot fixes will prevent future exploitation but will not remediate devices that are already compromised. If an attacker has been and gone, the hot fix is not a clean-up tool.

The FMC product line has been under sustained pressure. According to Acronis, researchers reported that Interlock ransomware exploited a separate Cisco Secure Firewall Management Center vulnerability, CVE-2026-20131, beginning in late January, a reminder that threat actors have been probing this attack surface for months and that patching FMC deployments is not a matter of routine hygiene, it is an active incident-response priority.

Customers are advised to upgrade to the latest software release immediately. For those who find the 23 July log entry in their systems, Cisco says the vulnerability ‘may have been exploited’ and recommends contacting TAC without delay.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version