Cisco Confirms Exploitation of Critical CVE-2026-20079 Flaw in Firewall Management Center
Cisco has confirmed active exploitation of the critical CVE-2026-20079 flaw in Secure Firewall Management Center. An unauthenticated attacker can execute commands with root privileges.

Cisco CVE-2026-20079 is a critical vulnerability in firewall management systems that the vendor has confirmed is being actively exploited. On September 9, 2026, Cisco updated its security advisory and said its PSIRT team learned of the attacks in August. The flaw allows an unauthenticated remote attacker to execute scripts and commands with root privileges.
The vulnerability is tracked as CVE-2026-20079 and has the maximum CVSS severity score of 10.0. On the same day, the U.S. agency CISA added it to the Known Exploited Vulnerabilities (KEV) catalog, which lists flaws known to be exploited in attacks.
Cisco CVE-2026-20079 Affects FMC and Cloud Management
The issue affects Cisco Secure Firewall Management Center (FMC) Software and the Cisco Security Cloud Control (SCC) Firewall Management service. According to Cisco, an attacker can exploit the flaw by sending crafted HTTP requests to the vulnerable interface.
Successful exploitation can lead to scripts and commands being executed as root on the affected management device. Compromising FMC could provide an attacker with root access to the device.
Cisco has already deployed a fix for the SCC Firewall Management SaaS service. For FMC deployments, the vendor has made hotfixes and fixed software versions available. The specific procedure depends on the version in use, and organizations should follow the relevant Cisco advisory.
No Workaround Is Available
Cisco says no workaround is available for CVE-2026-20079. Organizations using vulnerable FMC systems should therefore verify their version and promptly deploy the available hotfix or upgrade to a fixed release.
The vendor also warns that the hotfix will not remove an existing compromise of the device. Along with updating, administrators should therefore review system logs. Cisco lists /var/tmp/license.tmp as an indicator of compromise.
- verify whether the organization is running a vulnerable version of Cisco Secure FMC Software,
- deploy the hotfix or fixed release recommended by Cisco,
- review logs and check for the indicator /var/tmp/license.tmp,
- if compromise is suspected, conduct a forensic examination of the device, since the fix itself does not replace incident response.
CISA Set a Short Deadline for Federal Agencies
CISA added CVE-2026-20079 to the KEV catalog on September 9, 2026. According to the entry, U.S. federal civilian agencies must remediate it by September 12, 2026.
Cisco has not disclosed who is conducting the attacks, how many organizations were targeted, or when the campaign began. There is also no known information about subsequent attacker activity after access was obtained. The shared indicators of compromise and a July log entry may suggest earlier activity, but they do not by themselves confirm that all related incidents exploited this specific vulnerability.
Further developments will depend on whether Cisco publishes technical details, additional indicators of compromise, or attribution of the attacks. The results of examinations of FMC devices will also be important, especially where management interfaces were exposed to the internet.
Sources
- Cisco Security Advisory – Confirms active exploitation, the scope of vulnerable products, the impact of root access, the lack of a workaround, hotfixes, and the indicator of compromise.
- CISA Known Exploited Vulnerabilities Catalog – Confirms that CVE-2026-20079 was added to the KEV catalog and the required remediation under CISA guidance.
- BleepingComputer – Independently summarizes the Cisco update and notes that the vendor did not disclose attribution or the scope of the attacks.
Verified and updated: 09/10/2026 06:26



