Key takeaways
- Cisco confirmed on September 9, 2026 that CVE-2026-20079 had been actively exploited after PSIRT became aware of activity in August.
- The CVSS 10.0 vulnerability can allow an unauthenticated remote attacker to bypass FMC web-interface authentication, run scripts and commands, and obtain root access.
- Cisco has no workaround; affected on-premises Secure FMC deployments should receive the applicable Cisco hot fix or move to Cisco’s fixed software guidance.
- Cisco says a hot fix prevents future exploitation but may not remediate an already compromised system; suspected compromises require investigation and Cisco TAC engagement.
- FMC management interfaces should not be exposed to the public internet, and security teams should review Cisco’s log-based compromise indicator and Talos detection guidance.
Cisco updates advisory after exploitation is observed
Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication-bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software. The manufacturer updated its advisory on September 9, 2026, stating that its Product Security Incident Response Team became aware of exploitation during August. Cisco originally published the advisory on March 4, 2026. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-onprem-fmc-authbypass-5JPp45V2.html))
CVE-2026-20079 carries a CVSS base score of 10.0. Cisco says a remote attacker does not need to authenticate: crafted HTTP requests can exploit an improperly created system process, enabling execution of scripts and commands with root-level access to the underlying operating system. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-onprem-fmc-authbypass-5JPp45V2.html))
Why the FMC management plane warrants urgent attention
FMC is a centralized management system, so compromise can create a high-value foothold in environments that use it to administer firewall policy and connected security infrastructure. For facilities where firewall segmentation supports video surveillance, access control, building systems or operational networks, teams should treat the FMC management server as a critical administrative asset and validate both its software state and management-network exposure.
Cisco notes that keeping the FMC management interface off the public internet reduces the attack surface associated with this issue. That is risk reduction, not a substitute for remediation: Cisco states there are no workarounds for CVE-2026-20079 and recommends upgrading to fixed software. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-onprem-fmc-authbypass-5JPp45V2.html))
Apply the Cisco hot fix or fixed release for the deployed branch
Cisco’s advisory identifies affected Cisco Secure FMC Software and provides hot fixes for the 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 software branches. Rather than assuming a general firmware update resolves the issue, administrators should match the installed FMC release to Cisco’s advisory and Software Checker, then obtain and follow the applicable hot-fix or upgrade guidance. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-onprem-fmc-authbypass-5JPp45V2.html))
Cisco states that its SaaS-delivered Security Cloud Control Firewall Management environments have already received the fix as part of maintenance and require no customer action for this vulnerability. The immediate operational concern is therefore verifying the status of self-managed FMC systems and ensuring maintenance windows do not delay remediation. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-onprem-fmc-authbypass-5JPp45V2.html))
Patching alone is not a compromise assessment
Cisco explicitly cautions that the hot fix files are intended to prevent future exploitation and may not address an existing compromise. Its advisory directs customers that suspect exploitation to contact Cisco Technical Assistance Center for recovery guidance. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-onprem-fmc-authbypass-5JPp45V2.html))
As an initial check, Cisco provides a log-based indicator: in expert mode, administrators can search the system message logs for package_info activity associated with the path /var/tmp/license.tmp. A matching event may indicate the FMC was exploited and should trigger formal incident-response procedures rather than being treated as proof that the system is clean after patching. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-onprem-fmc-authbypass-5JPp45V2.html))
Cisco Talos links exploitation to post-compromise tooling
Cisco Talos reported tracking several clusters of malicious activity involving FMC vulnerabilities. In activity tied specifically to CVE-2026-20079, Talos observed web-shell deployment, a JAR-based command executor and credential theft. A separate cluster involved CVE-2026-20079 together with CVE-2026-20316, another FMC issue, and included reverse-shell and proxy tooling. ([blog.talosintelligence.com](https://blog.talosintelligence.com/fmc-ongoing-exploitation/))
Security teams should therefore pair emergency patching with a review of FMC logs, administrative accounts, unexpected files in the FMC web application environment, outbound connections and signs of credential access. Cisco Talos has published additional indicators of compromise and lists Snort SIDs 66075 through 66080 for CVE-2026-20079 detection coverage. ([blog.talosintelligence.com](https://blog.talosintelligence.com/fmc-ongoing-exploitation/))
Recommended actions for security and infrastructure teams
First, inventory every on-premises Secure FMC instance, identify its release branch, and apply Cisco’s applicable hot fix or fixed-release path on an expedited basis. Second, restrict management access to approved administrative networks or a controlled jump-host path; remove any direct internet exposure. Third, use Cisco’s advisory and Talos indicators to investigate for prior activity before assuming a patched appliance is trustworthy. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-onprem-fmc-authbypass-5JPp45V2.html))
Finally, coordinate the response across network, security operations and facility-technology owners. An FMC appliance may sit at the boundary between enterprise and physical-security or industrial segments; recovery planning should account for firewall-policy backups, controlled credential resets and validation of managed-device connectivity after remediation. This is an operational recommendation based on the privileged role of centralized firewall management, not an indication that every FMC deployment has been compromised.
