Cisco Secure FMC CVE-2026-20079: Auth Bypass to Root — Patch ≠ Clean

By George Bailey   Published: 09/15/26   Updated: 09/15/26   3 min read

The box that manages your Cisco firewalls should not skip login. CVE-2026-20079 is a CVSS 10.0 authentication bypass in Secure Firewall Management Center that yields root — and Cisco plus Talos say it is being abused by nation-state and ransomware clusters.

Hotfixes stop the next attempt. They do not clean a box that already grew a webshell or a malicious license.tmp.

What happened

Cisco disclosed the FMC web-interface authentication bypass in March 2026: an improper system process created at boot lets an unauthenticated attacker send crafted HTTP requests and execute scripts/commands as root. Cloud-hosted Security Cloud Control Firewall Management was patched by Cisco; on-prem FMC needs the hotfixes.

On September 9, 2026, Cisco updated the advisory to confirm active exploitation (PSIRT awareness in August). CISA added it to KEV with a federal due date of September 12. Talos described intrusion clusters including activity consistent with Sandworm and a suspected Qilin ransomware operator, often alongside companion static-credential issue CVE-2026-20316.

Cisco plans a broader hardening release the week of September 16 — but recommends applying the existing hotfixes immediately rather than waiting.

Why it matters

FMC holds the keys to managed firewalls: policies, objects, and often credentials worth stealing. Root on FMC is a whole-fleet problem.

Cisco is explicit: hotfixes prevent future exploitation and may not remediate an already compromised device — contact TAC if IoCs hit.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.