Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication bypass vulnerability affecting Cisco Secure Firewall Management Center (FMC) software. The vulnerability carries the maximum CVSS score of 10.0 and allows unauthenticated remote attackers to bypass authentication and execute scripts and commands with root privileges on vulnerable systems.

The vulnerability was originally disclosed in March 2026 without evidence of exploitation. On 9 September 2026, Cisco updated its advisory to confirm that its Product Security Incident Response Team (PSIRT) became aware of active exploitation in August 2026.

Due to confirmed exploitation and the privileged access available upon compromise, organizations using Cisco FMC should prioritize remediation immediately.

CVE-2026-20079

Description: Authentication Bypass
CVSS Score: 10.0 (Critical)
Attack Vector: Remote, Unauthenticated

The vulnerability exists within the web interface of Cisco Secure Firewall Management Center software and is caused by an improper system process created during system boot. An attacker can exploit the flaw by sending crafted HTTP requests to a vulnerable device. Successful exploitation allows execution of scripts and commands with root-level privileges on the underlying operating system.

Cisco states the vulnerability affects:

  • Cisco Secure FMC Software
  • Cisco Security Cloud Control Firewall Management

Cisco has already deployed fixes to the cloud-hosted Security Cloud Control service

Active Exploitation Confirmed

Cisco confirmed that active exploitation of CVE-2026-20079 has been observed and updated its advisory accordingly. The vendor has not disclosed when attacks began, the identities of the threat actors involved, or detailed post-compromise activity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog and directed U.S. federal agencies to remediate affected systems by 12 September 2026.

Mitigation and Remediation

Immediate Actions

  1. Identify all Cisco Secure FMC deployments.
  2. Upgrade vulnerable systems to Cisco-fixed software releases.
  3. Verify cloud-managed Security Cloud Control deployments are operating on Cisco-patched infrastructure.
  4. Review FMC systems for indicators of compromise.
  5. Conduct credential hygiene activities if compromise is suspected.

Cisco has stated that no workarounds are available for this vulnerability. Applying vendor patches is the primary mitigation strategy.

Additionally, patching prevents future exploitation but does not remediate systems that may already be compromised. Organisations identifying indicators of compromise should perform incident response investigations and engage Cisco support as appropriate.

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation. 

 

Contact Us