Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cisco says its Product Security Incident Response Team became aware in August 2026 that attackers were exploiting CVE-2026-20079, a critical authentication-bypass flaw in Cisco Secure Firewall Management Center (FMC). Rated CVSS 10.0, it could let an unauthenticated remote attacker run commands as root on the underlying operating system. Cisco recommends upgrading to a fixed release; it says there is no workaround.

What Cisco’s critical firewall-flaw warning refers to

The headline refers to CVE-2026-20079, a vulnerability in the web interface of Cisco FMC. Cisco’s advisory was first published March 4, 2026, and updated September 16, 2026. Cisco says PSIRT became aware of active exploitation in August 2026; that is when the company says it learned of attacks, not necessarily when the attacks began.

The vulnerable process is created improperly at boot. An attacker who can reach the FMC web interface can send crafted HTTP requests without authenticating. Successful exploitation can allow scripts and commands to run with root access to the underlying operating system.

Which Cisco products are affected?

For CVE-2026-20079, Cisco lists FMC and its SaaS-delivered Security Cloud Control Firewall Management offering as affected. Cisco says it has deployed the fix to that SaaS offering, so its users do not need to take action for this vulnerability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The same advisory says the flaw does not affect Firewall Device Manager, ASA software, FTD software, or Security Cloud Control (formerly Defense Orchestrator). These scope statements apply to CVE-2026-20079 specifically; other Cisco firewall vulnerabilities affect different products and features.

What to do if you run FMC

  1. Identify the product and release. Check the deployed product and exact software version. Do not assume that an ASA or FTD fixed release applies to FMC, or vice versa.
  2. Match the version to Cisco’s current advisory. Cisco lists the first fixed FMC releases as 7.0.10 for 7.0 and earlier, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2, and 10.1.0. Use Cisco’s Software Checker with your installed product and release to confirm the applicable advisory and fixed version; check the live advisory because its details may change.
  3. Upgrade to the applicable fixed release. Cisco says no workaround addresses CVE-2026-20079 and strongly recommends upgrading. Restricting public-internet access to the FMC management interface reduces exposure, but is not a substitute for applying the fix.

How to check for possible compromise

Cisco’s advisory gives this indicator check for FMC. In expert mode, run:

zgrep "package_info.*license" messages*

An entry showing /var/tmp/license.tmp may indicate exploitation. It is an indicator to investigate, not proof on its own of which vulnerability was used or a complete determination of compromise. If exploitation is suspected, Cisco says to contact its Technical Assistance Center (TAC) immediately. Cisco also cautions that hot-fix files can prevent future exploitation but may not remediate an intrusion that has already occurred; do not treat patching alone as incident recovery.

Rank #2
Cisco Systems Firepower 1140 Network Security/Firewall Appliance - 8 Port - 1000Base-T - Gigabit Ethernet - 8 x RJ-45-4 Total Expansion Slots - 1U - Rack-mountable (FPR1140-NGFW-K9)
  • Firewall Protection Supported: Malware Protection
  • Firewall Protection Supported: Threat Protection
  • Firewall Protection Supported: URL Filtering
  • Firewall Protection Supported: Intrusion Prevention
  • Total Number of Ports: 8

How this flaw differs from other Cisco firewall reports

Several Cisco vulnerability reports involve FMC or firewall software, but their impact, affected products, and exploitation statements differ. Use the CVE and affected release—not the phrase “critical firewall flaw”—to identify the right remediation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
CVE Affected product and impact Cisco severity Exploitation statement Response
CVE-2026-20079 FMC web interface; unauthenticated remote attacker may gain root access to the underlying operating system. CVSS 10.0, Critical. Cisco says PSIRT became aware of active exploitation in August 2026. Upgrade FMC to the applicable fixed release listed above; investigate the specified log indicator and contact TAC if compromise is suspected.
CVE-2026-20316 FMC static-credential flaw; an unauthenticated attacker can log in with a low-privilege account and access sensitive data. Cisco says FMC is affected regardless of device configuration. CVSS 5.3; Cisco assigns a High Security Impact Rating because the flaw can be chained with other FMC vulnerabilities to elevate privileges. Cisco says PSIRT became aware of active exploitation in July 2026. Singapore’s Cyber Security Agency described the issue as reportedly under active exploitation in its July 31, 2026 alert. Use the separate CVE-2026-20316 advisory for its affected releases and remediation. Its advisory also mentions /var/tmp/license.tmp; that shared example does not identify which vulnerability was used.
CVE-2026-20349 ASA and FTD remote-access SSL VPN; a crafted HTTP request to a vulnerable service can cause the device to reload, creating a denial of service. CVSS 8.6. Cisco says PSIRT became aware of active exploitation in August 2026. Check the version-specific fixed-release table in the CVE-2026-20349 advisory. Cisco says no workaround addresses this flaw.
CVE-2026-76412, CVE-2026-76413, CVE-2026-76420 Separate FMC vulnerabilities: an unauthenticated peer-impersonation route to root under a stated connection condition, an authenticated privilege escalation, and an SSO-token-forgery issue. Critical group advisory, CVSS base 9.0. In its September 16, 2026 advisory, Cisco said it was not aware of public announcements or malicious use of these vulnerabilities. Consult the September advisory for the affected releases and fixes; do not infer exploitation from the severity rating.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why exposure and severity are not the same question

For CVE-2026-20079, public-internet reachability of the FMC management interface increases the attack surface, but a privately reachable or otherwise restricted interface does not change the advisory’s recommendation to upgrade. Conversely, a high CVSS score alone does not tell you whether a particular organization’s product, version, or configuration is affected. Confirm those details against the relevant Cisco advisory and Software Checker.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.