Cisco has confirmed that CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center, is being actively exploited, with its PSIRT saying it became aware of exploitation activity in August 2026. With a CVSS score of 10.0 and root-level compromise possible over the network, UK teams running FMC should treat this as an immediate patching priority.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Flaw disclosed | 0 | 4 |
| IOCs and hotfix | 20 | 2 |
| PSIRT confirms exploit | 23 | 2 |
| Exploitation confirmed | 26 | 1 |
| KEV deadline | 27 | 1 |
What Cisco has confirmed about CVE-2026-20079
Cisco updated its advisory on Wednesday to state that its PSIRT became aware of active exploitation of CVE-2026-20079 in August 2026, according to BleepingComputer. The flaw sits in the web interface of Secure Firewall Management Center software and stems from an improper system process created at boot time. Cisco says an unauthenticated remote attacker can bypass authentication and execute script files to obtain root access; BleepingComputer reports that this allows attackers to execute scripts and commands as root on the underlying operating system.
The vulnerability affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management. Cisco says it has already patched the cloud-hosted Security Cloud Control service, but on-premises Secure FMC deployments remain exposed until administrators apply the update themselves. Crucially, Cisco states there are no workarounds — software upgrades are the only route to remediation.
Why a firewall management flaw carries maximum severity
FMC is not a peripheral system — it is the control plane that configures policy across an organisation's Cisco firewall estate. A root-level compromise of the management centre gives an attacker the ability to alter firewall rules, intercept traffic policy and pivot into the wider network, which is why Cisco assigned this flaw its top CVSS rating of 10.0.
For teams that depend on centralised firewall administration, this is a stark reminder that strengthening your overall network security posture has to include the management infrastructure itself, not just the firewalls it controls. An attacker with root on FMC effectively holds the keys to the perimeter.
A murky exploitation timeline: from July IOCs to August confirmation
Cisco first disclosed CVE-2026-20079 in March 2026, saying at the time it had no evidence of exploitation. That changed on 29 July, when Cisco disclosed a separate, High-severity Secure FMC flaw, CVE-2026-20316, involving static credentials on a low-privileged account — and confirmed that flaw had been actively exploited. Cisco also updated the CVE-2026-20079 advisory to include the same indicators of compromise as CVE-2026-20316, without confirming exploitation of the auth-bypass flaw itself.
The shared indicator pointed administrators to check /var/log/messages for entries referencing /var/tmp/license.tmp, with Cisco's example log entry dated 23 July — three weeks before Cisco says its PSIRT became aware of active exploitation of CVE-2026-20079 in August. Cisco has not clarified whether the July activity involved both vulnerabilities together, but the shared indicators, identical hot fixes and the timing gap all point to a plausible overlap. Cisco advises anyone who finds these indicators to contact its Technical Assistance Center, warning that applying the hot fix stops future exploitation but does not remediate a device that has already been compromised.

Part of a wider pattern hitting Secure FMC in 2026
This is the second maximum- or high-severity FMC flaw confirmed as exploited within weeks: CVE-2026-20316 (static credentials, High severity) in July, and now CVE-2026-20079 (authentication bypass, CVSS 10.0) in August.
Taken together, this is not an isolated incident but a recurring pattern of attackers probing and weaponising Secure FMC vulnerabilities across the year. Teams that manage inventory of firewall estates should implement robust vulnerability management practices that specifically track FMC advisories, since Cisco has shown it will continue updating exploitation status on advisories well after initial disclosure.
What UK infrastructure teams should do now
Given there is no workaround, the only defensible position is to upgrade to the patched software release without delay and check logs for the indicators Cisco has published. Anyone finding evidence of the July 23 log pattern should assume compromise and engage Cisco TAC rather than relying on the patch alone to clean an affected device.
Organisations reviewing their broader Cisco estate should also implement robust vulnerability management practices and stay informed on other critical Cisco vulnerabilities disclosed this year, since FMC has not been the only Cisco product line affected. Teams running older, unsupported hardware alongside FMC may also want to consider third-party maintenance for your Cisco infrastructure where upgrade paths are constrained, and to explore our range of Cisco products when planning refresh cycles around supported release trains.
The CISA KEV deadline and what it means outside the US
CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalogue on the day Cisco confirmed exploitation, ordering US Federal Civilian Executive Branch agencies to secure vulnerable systems by 12 September 2026. That deadline is a US federal mandate, but its inclusion in KEV is a reliable signal of confirmed real-world exploitation that UK buyers should treat as an urgency marker regardless of jurisdiction.
For UK critical national infrastructure operators and enterprises running Secure FMC, the practical takeaway is the same: this is not a theoretical risk awaiting a proof of concept, it is an actively exploited maximum-severity flaw in a widely deployed management platform.
- 01BleepingComputer — Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks · 9 September 2026
- 02Cisco Security Advisory — Secure FMC Authentication Bypass Vulnerability · 9 September 2026
- 03The Hacker News — Cisco FMC zero-day actively exploited · 29 July 2026
