The box that manages your Cisco firewalls should not skip login. CVE-2026-20079 is a CVSS 10.0 authentication bypass in Secure Firewall Management Center that yields root — and Cisco plus Talos say it is being abused by nation-state and ransomware clusters.
Hotfixes stop the next attempt. They do not clean a box that already grew a webshell or a malicious license.tmp.
What happened
Cisco disclosed the FMC web-interface authentication bypass in March 2026: an improper system process created at boot lets an unauthenticated attacker send crafted HTTP requests and execute scripts/commands as root. Cloud-hosted Security Cloud Control Firewall Management was patched by Cisco; on-prem FMC needs the hotfixes.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
On September 9, 2026, Cisco updated the advisory to confirm active exploitation (PSIRT awareness in August). CISA added it to KEV with a federal due date of September 12. Talos described intrusion clusters including activity consistent with Sandworm and a suspected Qilin ransomware operator, often alongside companion static-credential issue CVE-2026-20316.
Cisco plans a broader hardening release the week of September 16 — but recommends applying the existing hotfixes immediately rather than waiting.
Why it matters
FMC holds the keys to managed firewalls: policies, objects, and often credentials worth stealing. Root on FMC is a whole-fleet problem.
Cisco is explicit: hotfixes prevent future exploitation and may not remediate an already compromised device — contact TAC if IoCs hit.
What to do first
- Apply the Cisco Secure FMC hotfixes for your train (7.0 / 7.2 / 7.4 / 7.6 / 7.7 / 10.0 packages named in the advisory) now — do not wait for the hardening bundle.
- Ensure the FMC management interface is not internet-reachable; limit to jump hosts.
- In expert mode, hunt:
zgrep "package_info.*license" /var/log/messages*— hits referencing/var/tmp/license.tmpmay indicate exploitation. - If IoCs appear: contact Cisco TAC for recovery guidance before trusting a “patched and done” narrative; rotate credentials harvested from managed devices.
- Review Talos IoCs for webshells under CSM Tomcat webroot and unexpected JAR drops.
Details
- CVE: CVE-2026-20079 (CVSS 10.0); related exploited CVE-2026-20316 (static credentials)
- Product: Cisco Secure Firewall Management Center (on-prem); SCC Firewall Management patched by Cisco
- Not affected: FDM, ASA, FTD software (per Cisco)
- KEV: Added 2026-09-09; federal due 2026-09-12
- Workarounds: None — network restriction reduces exposure only
Hunt / verify
- Confirm hotfix installed on every FMC.
- Run the package_info / license.tmp zgrep IoC check; review Tomcat webroot for unexpected shells/JARs.
- Audit managed-firewall config pulls and admin sessions since July.
Sources
- Cisco PSIRT: Secure FMC Authentication Bypass (CVE-2026-20079)
- BleepingComputer: Cisco confirms FMC flaw exploited
- Help Net Security: Talos — Sandworm and ransomware clusters on FMC bugs
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.