UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

Cisco Secure FMC CVE-2026-20079: UK Patch Alert 2026

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

Cisco has confirmed that CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center, is being actively exploited, with its PSIRT saying it became aware of exploitation activity in August 2026. With a CVSS score of 10.0 and root-level compromise possible over the network, UK teams running FMC should treat this as an immediate patching priority.

CVE-2026-20079 disclosure to exploitation confirmation
W0W5W10W15W20W25W28Flaw disclosed4wIOCs and hotfix2wPSIRT confirms exploit2wExploitation confirmed1wKEV deadline1wTotal: 28 weeks end-to-end
View the data behind this chart
CVE-2026-20079 disclosure to exploitation confirmation
PhaseStarts (week)Duration (weeks)
Flaw disclosed04
IOCs and hotfix202
PSIRT confirms exploit232
Exploitation confirmed261
KEV deadline271

What Cisco has confirmed about CVE-2026-20079

Cisco updated its advisory on Wednesday to state that its PSIRT became aware of active exploitation of CVE-2026-20079 in August 2026, according to BleepingComputer. The flaw sits in the web interface of Secure Firewall Management Center software and stems from an improper system process created at boot time. Cisco says an unauthenticated remote attacker can bypass authentication and execute script files to obtain root access; BleepingComputer reports that this allows attackers to execute scripts and commands as root on the underlying operating system.

The vulnerability affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management. Cisco says it has already patched the cloud-hosted Security Cloud Control service, but on-premises Secure FMC deployments remain exposed until administrators apply the update themselves. Crucially, Cisco states there are no workarounds — software upgrades are the only route to remediation.

Why a firewall management flaw carries maximum severity

FMC is not a peripheral system — it is the control plane that configures policy across an organisation's Cisco firewall estate. A root-level compromise of the management centre gives an attacker the ability to alter firewall rules, intercept traffic policy and pivot into the wider network, which is why Cisco assigned this flaw its top CVSS rating of 10.0.

For teams that depend on centralised firewall administration, this is a stark reminder that strengthening your overall network security posture has to include the management infrastructure itself, not just the firewalls it controls. An attacker with root on FMC effectively holds the keys to the perimeter.

A murky exploitation timeline: from July IOCs to August confirmation

Cisco first disclosed CVE-2026-20079 in March 2026, saying at the time it had no evidence of exploitation. That changed on 29 July, when Cisco disclosed a separate, High-severity Secure FMC flaw, CVE-2026-20316, involving static credentials on a low-privileged account — and confirmed that flaw had been actively exploited. Cisco also updated the CVE-2026-20079 advisory to include the same indicators of compromise as CVE-2026-20316, without confirming exploitation of the auth-bypass flaw itself.

The shared indicator pointed administrators to check /var/log/messages for entries referencing /var/tmp/license.tmp, with Cisco's example log entry dated 23 July — three weeks before Cisco says its PSIRT became aware of active exploitation of CVE-2026-20079 in August. Cisco has not clarified whether the July activity involved both vulnerabilities together, but the shared indicators, identical hot fixes and the timing gap all point to a plausible overlap. Cisco advises anyone who finds these indicators to contact its Technical Assistance Center, warning that applying the hot fix stops future exploitation but does not remediate a device that has already been compromised.

Illustration: Cisco Secure FMC CVE-2026-20079: UK Patch Alert 2026

Part of a wider pattern hitting Secure FMC in 2026

This is the second maximum- or high-severity FMC flaw confirmed as exploited within weeks: CVE-2026-20316 (static credentials, High severity) in July, and now CVE-2026-20079 (authentication bypass, CVSS 10.0) in August.

Taken together, this is not an isolated incident but a recurring pattern of attackers probing and weaponising Secure FMC vulnerabilities across the year. Teams that manage inventory of firewall estates should implement robust vulnerability management practices that specifically track FMC advisories, since Cisco has shown it will continue updating exploitation status on advisories well after initial disclosure.

What UK infrastructure teams should do now

Given there is no workaround, the only defensible position is to upgrade to the patched software release without delay and check logs for the indicators Cisco has published. Anyone finding evidence of the July 23 log pattern should assume compromise and engage Cisco TAC rather than relying on the patch alone to clean an affected device.

Organisations reviewing their broader Cisco estate should also implement robust vulnerability management practices and stay informed on other critical Cisco vulnerabilities disclosed this year, since FMC has not been the only Cisco product line affected. Teams running older, unsupported hardware alongside FMC may also want to consider third-party maintenance for your Cisco infrastructure where upgrade paths are constrained, and to explore our range of Cisco products when planning refresh cycles around supported release trains.

The CISA KEV deadline and what it means outside the US

CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalogue on the day Cisco confirmed exploitation, ordering US Federal Civilian Executive Branch agencies to secure vulnerable systems by 12 September 2026. That deadline is a US federal mandate, but its inclusion in KEV is a reliable signal of confirmed real-world exploitation that UK buyers should treat as an urgency marker regardless of jurisdiction.

For UK critical national infrastructure operators and enterprises running Secure FMC, the practical takeaway is the same: this is not a theoretical risk awaiting a proof of concept, it is an actively exploited maximum-severity flaw in a widely deployed management platform.

Share
Key takeaways
  • CVE-2026-20079 is a maximum-severity (CVSS 10.0) authentication bypass in Cisco Secure FMC, now confirmed as actively exploited.
  • There is no workaround — Cisco says upgrading to the latest software release is the only remediation path.
  • Hot fixes stop future exploitation but do not remediate devices already compromised; check logs for published indicators of compromise.
  • This follows a pattern of FMC-targeted exploitation in 2026, including CVE-2026-20316 and CVE-2026-20131, so ongoing vulnerability tracking is essential.
Frequently asked

FAQs — Cisco Secure FMC CVE-2026-20079

What is CVE-2026-20079?

It is a maximum-severity authentication bypass in Cisco Secure Firewall Management Center software, with a CVSS score of 10.0, allowing unauthenticated remote attackers to execute scripts and commands as root.

Is CVE-2026-20079 being actively exploited?

Yes. Cisco updated its advisory to confirm its PSIRT became aware of active exploitation in August 2026, and CISA has since added the flaw to its Known Exploited Vulnerabilities catalogue.

Is there a workaround for CVE-2026-20079?

No. Cisco states there are no workarounds and recommends customers upgrade to the latest software release as the only remediation.

Does patching remove an existing compromise?

No. Cisco warns that applying the hot fix prevents future exploitation but does not remediate a device that has already been compromised; affected organisations should contact Cisco TAC.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111