Cisco Secure FMC Flaw Actively Exploited, Poses Root-Level Threat
A critical authentication bypass vulnerability, **CVE-2026-20079**, in **Cisco's Secure Firewall Management Center (FMC)** software is now confirmed to be under active exploitation. This maximum-severity flaw (CVSS 10.0) allows unauthenticated, remote attackers to gain root access and execute arbitrary commands, prompting urgent calls for patching.

**Cisco** has issued an urgent update confirming active exploitation of a maximum-severity authentication bypass vulnerability, **CVE-2026-20079**, in its **Secure Firewall Management Center (FMC)** software.
Rated with a CVSS score of 10.0, this critical flaw enables unauthenticated, remote attackers to bypass authentication mechanisms and execute scripts and commands with root privileges on affected devices.
"In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," **Cisco** stated in an update to its security advisory on Wednesday. The company has not yet disclosed details regarding the start date of the attacks, the actors involved, or the observed post-exploitation activities.
**Cisco** initially disclosed **CVE-2026-20079** in March, at which point there was no evidence of in-the-wild exploitation. The vulnerability stems from an improperly configured system process created during boot time and can be triggered by sending specially crafted HTTP requests to the web interface of a vulnerable device.
Successful exploitation grants an unauthenticated attacker complete control over the device. The vulnerability impacts **Cisco Secure FMC Software** and **Cisco Security Cloud Control Firewall Management**. **Cisco** has already patched its cloud-hosted **Security Cloud Control** service.
Given the severity and active exploitation, **Cisco** emphasizes that no workarounds exist and strongly recommends customers upgrade to the latest software release immediately.
Today, the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** added **CVE-2026-20079** to its Known Exploited Vulnerabilities (KEV) catalog. Federal Civilian Executive Branch agencies have been mandated to secure vulnerable systems by September 12, 2026.
## Evidence of Exploitation May Have Surfaced Earlier
While **Cisco**'s security team became aware of active exploitation in August, indicators of compromise (IOCs) published in a July advisory update suggest the flaw might have been exploited earlier.
On July 29, **Cisco** disclosed another **Secure FMC** vulnerability, **CVE-2026-20316**, related to static credentials for a low-privileged account. This flaw was also confirmed to be actively exploited, rated as High severity, as it could be combined with other vulnerabilities for privilege escalation.
Interestingly, **Cisco** updated the **CVE-2026-20079** advisory to include the same IOCs as **CVE-2026-20316** at that time, though without explicitly confirming exploitation of the authentication bypass.
Administrators were advised to search `/var/log/messages` for activity related to `/var/tmp/license.tmp`, with an example log entry provided:
**Cisco** noted that the presence of this entry indicates that the vulnerability "may have been exploited." The timestamp of July 23 in the example predates **Cisco PSIRT**'s August awareness of **CVE-2026-20079** exploitation by several weeks.
Furthermore, identical hotfixes were released for both **CVE-2026-20316** and **CVE-2026-20079**, strongly suggesting a connection between the two and their potential use in tandem during attacks.
While **Cisco** has now confirmed exploitation of **CVE-2026-20079**, it has not clarified whether the July 23 activity involved both vulnerabilities. However, the shared IOCs, identical hotfixes, and the early log entry strongly imply that both flaws might have been leveraged in the same attack campaigns.
Customers who discover these indicators of compromise are urged to contact the **Cisco Technical Assistance Center (TAC)** for support. **Cisco** warns that while installing hotfixes will prevent future exploitation, it will not remediate devices that have already been compromised.