Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.
The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices.
“In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability,” Cisco updated its CVE-2026-20079 advisory to say on Wednesday.
Cisco did not disclose when the attacks began, who was behind them, or what post-exploitation activity was observed.
Cisco first disclosed CVE-2026-20079 in March, when the company said it had no evidence that the vulnerability was being exploited in attacks.
The flaw is caused by an improper system process created at boot time and can be exploited by sending crafted HTTP requests to the web interface of an affected device.
A successful attack can allow an unauthenticated attacker to execute scripts and commands on the device with root privileges.
The vulnerability affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management. Cisco says it has already patched the cloud-hosted Security Cloud Control service.
Cisco says there are no workarounds and recommends that customers upgrade to the latest software release.
Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
Evidence of exploitation appeared in July
While Cisco says its security team became aware of active exploitation of CVE-2026-20079 in August, IOCs published in a July advisory update suggest the flaw may have been exploited earlier.
On July 29, Cisco disclosed another Secure FMC vulnerability, tracked as CVE-2026-20316, caused by static credentials for a low-privileged account.
Cisco said at the time that CVE-2026-20316 had been actively exploited in attacks and assigned it a High severity rating because the access could be combined with other Secure FMC vulnerabilities to elevate privileges.
As BleepingComputer reported at the time, Cisco also updated the CVE-2026-20079 advisory to include the same indicators as CVE-2026-20316, but did not confirm the flaw was exploited.
Cisco told administrators to search /var/log/messages for activity related to /var/tmp/license.tmp and shared the following example log entry:
Jul 23 16:16:33 firepower sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsmCisco says that if this entry is found, the vulnerability “may have been exploited” on the examined Secure FMC device.
The example log entry is dated July 23, weeks before Cisco says PSIRT became aware of exploitation of CVE-2026-20079 in August.
Cisco also released the same Secure FMC hot fixes for both CVE-2026-20316 and CVE-2026-20079.
At the time, BleepingComputer contacted Cisco to ask whether the two vulnerabilities were connected, whether CVE-2026-20079 had also been exploited, and whether Cisco intentionally added the shared indicator to both advisories.
Cisco did not answer the questions directly and instead shared the following statement:
“On July 29, 2026, Cisco released software fixes to address vulnerabilities in Cisco Secure Firewall Management Center (FMC). Details are outlined in the security advisories (Static Credential vulnerability, Authentication Bypass vulnerability), and Cisco strongly recommends customers immediately apply the available fixes,” a Cisco spokesperson told BleepingComputer.
“Customers needing support should contact the Cisco Technical Assistance Center (TAC).”
Cisco’s latest update now confirms that CVE-2026-20079 has been exploited, but does not clarify whether the July 23 activity included exploitation of both vulnerabilities.
However, the same IOCs for both flaws, identical July hot fixes, and the July 23 log entry suggest both vulnerabilities may have been used in the same attacks.
Cisco advises customers who discover the indicators of compromise to contact its TAC for support, warning that installing the hot fixes will prevent future exploitation but will not remediate devices already compromised.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

