The vulnerability, tracked as CVE-2026-20079, carries a maximum CVSS score of 10.0 and allows unauthenticated remote attackers to bypass authentication and execute scripts and commands with root privileges on vulnerable devices. Cisco first disclosed the flaw in March 2026, stating at the time that there was no evidence of exploitation.
According to an update to Cisco's advisory on Wednesday, the company's Product Security Incident Response Team (PSIRT) became aware of active exploitation in August 2026. Cisco did not disclose when the attacks began, who was behind them, or what post-exploitation activity was observed.
However, indicators of compromise (IOCs) published in a July 29 advisory update for a related Secure FMC vulnerability suggest the flaw may have been exploited earlier. Cisco advised administrators to check /var/log/messages for activity related to /var/tmp/license.tmp and provided a sample log entry dated July 23. Cisco said that if this entry is found, the vulnerability "may have been exploited" on the examined device.
The flaw stems from an improper system process created at boot time and can be exploited by sending crafted HTTP requests to the web interface. It affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management. Cisco says the cloud-hosted Security Cloud Control service has already been patched, but there are no workarounds for on-premises deployments; the company recommends upgrading to the latest software release.
The July 29 advisory disclosed a separate Secure FMC vulnerability (CVE-2026-20316) caused by static credentials for a low-privileged account, which Cisco said was already being actively exploited and could be combined with other flaws to elevate privileges. The indicators published for that vulnerability matched those later associated with CVE-2026-20079.