Cisco Confirms Active Exploitation of Maximum-Severity Secure FMC Flaw

CISA orders federal agencies to patch CVE-2026-20079 by September 12 as evidence suggests attacks began weeks before disclosure

edit
By LineZotpaper
Published
Read Time2 min
Cisco has confirmed that a critical authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities catalog and order federal agencies to secure affected systems by September 12, 2026.

The vulnerability, tracked as CVE-2026-20079, carries a maximum CVSS score of 10.0 and allows unauthenticated remote attackers to bypass authentication and execute scripts and commands with root privileges on vulnerable devices. Cisco first disclosed the flaw in March 2026, stating at the time that there was no evidence of exploitation.

According to an update to Cisco's advisory on Wednesday, the company's Product Security Incident Response Team (PSIRT) became aware of active exploitation in August 2026. Cisco did not disclose when the attacks began, who was behind them, or what post-exploitation activity was observed.

However, indicators of compromise (IOCs) published in a July 29 advisory update for a related Secure FMC vulnerability suggest the flaw may have been exploited earlier. Cisco advised administrators to check /var/log/messages for activity related to /var/tmp/license.tmp and provided a sample log entry dated July 23. Cisco said that if this entry is found, the vulnerability "may have been exploited" on the examined device.

The flaw stems from an improper system process created at boot time and can be exploited by sending crafted HTTP requests to the web interface. It affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management. Cisco says the cloud-hosted Security Cloud Control service has already been patched, but there are no workarounds for on-premises deployments; the company recommends upgrading to the latest software release.

The July 29 advisory disclosed a separate Secure FMC vulnerability (CVE-2026-20316) caused by static credentials for a low-privileged account, which Cisco said was already being actively exploited and could be combined with other flaws to elevate privileges. The indicators published for that vulnerability matched those later associated with CVE-2026-20079.

§

Analysis

Why This Matters

  • Organizations using Cisco Secure FMC face immediate risk of full system compromise, as the flaw requires no authentication and grants root access.
  • CISA's inclusion in the KEV catalog creates a binding operational directive for U.S. federal agencies, with a tight three-day remediation deadline.
  • The gap between first disclosure (March) and confirmed exploitation (August) highlights the window attackers have to reverse-engineer patches before administrators apply them.

Background

Cisco's Secure Firewall Management Center is a central management platform for the company's firewall product line, widely deployed in enterprise and government networks. Authentication bypass vulnerabilities in such systems are particularly dangerous because they can allow attackers to pivot across segmented networks. Cisco regularly publishes security advisories, but the company has faced criticism in the past for slow disclosure of actively exploited zero-days. The dual disclosure of CVE-2026-20316 and CVE-2026-20079 within weeks suggests a coordinated campaign targeting FMC appliances.

Key Perspectives

Cisco: The company has released patch guidance and updated advisories as evidence of exploitation emerged, recommending immediate upgrades. It has not attributed the attacks or disclosed the attack vector beyond the technical details. CISA: By adding the vulnerability to the KEV catalog, the agency signals high risk to critical infrastructure and mandates patching for federal civilian agencies within a short timeframe, though private sector adoption remains voluntary. Security Researchers: The July indicators suggest attackers may have been exploiting the flaw since at least late July, weeks before Cisco officially confirmed active attacks. Researchers may push for faster public disclosure of exploitation evidence when IOCs are shared in related advisories.

What to Watch

  • Whether Cisco releases additional IOCs or forensic details as the investigation continues.
  • Reports of exploitation in non-federal networks, particularly in critical infrastructure or telecommunications.
  • The effectiveness of CISA's September 12 deadline and any subsequent emergency directives if widespread attacks emerge.
  • Potential release of proof-of-concept exploit code, which could fuel broader criminal use.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.