P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Cisco confirms exploitation of CVE-2026-20079. An FMC web request can lead to root.

Cisco’s 9 September update confirms attackers are exploiting a 10.0 authentication bypass in Secure Firewall Management Center. There is no workaround, and installing a hotfix does not answer whether a device was already compromised.

By Parminder Kumar Sharma · · 3 min read

AI-generated editorial photograph of an unbranded firewall management appliance with an open panel and red warning light.

The advisory moved from critical exposure to confirmed exploitation

Cisco first published its CVE-2026-20079 advisory in March. On 9 September it updated the record to say PSIRT had become aware of active exploitation.

The flaw sits in the Secure Firewall Management Center web interface. Cisco says an unauthenticated remote attacker can send crafted HTTP requests, bypass authentication and execute scripts or commands as root. The CVSS base score is 10.0.

Public internet exposure increases the attack surface, but Cisco says the affected software is vulnerable regardless of configuration. Removing direct internet access reduces risk while patching; it is not remediation.

Cisco FMC vulnerability summary showing CVSS 10.0, unauthenticated root access and confirmed exploitation.
Original editorial visual by P.K. Sharma.

FMC is affected; ASA and FTD software are not

Cisco lists Secure FMC Software and SCC Firewall Management as affected. The SaaS SCC Firewall Management environment has already been updated by Cisco. Customers do not need to act on that hosted service.

Cisco lists Firewall Device Manager, ASA Software, FTD Software and the separate Security Cloud Control service as not vulnerable. Product names are similar, so asset inventory must identify the actual management component and version.

Vendor status by product

ProductStatusAction
Secure FMC SoftwareAffectedUse Software Checker and apply fixed release or hotfix
SCC Firewall ManagementAffected, vendor updatedNo customer action
ASA SoftwareNot vulnerableNo action for this CVE
FTD SoftwareNot vulnerableNo action for this CVE
Firewall Device ManagerNot vulnerableNo action for this CVE

Patch and compromise assessment are separate jobs

Cisco publishes an expert-mode log check for a suspicious invocation of its package information script referencing a temporary licence file. Administrators should use the exact command and output example in the advisory, preserve relevant logs and contact Cisco TAC if the indicator appears.

Cisco warns that its hotfix files prevent future exploitation and may not address an existing compromise. A confirmed indicator therefore needs incident response, credential and trust review, and recovery guidance from TAC. Do not treat a successful patch as proof that the device was clean beforehand.

The position

A firewall manager with unauthenticated root compromise is an emergency because it controls a security boundary and contains high-value configuration. The absence of a workaround and Cisco’s exploitation confirmation make this a patch-and-hunt event, not a routine maintenance ticket.

The management interface should be reachable only from tightly controlled administration networks. That architecture limits exposure to this class of flaw and gives responders clearer logs when unexpected requests arrive.

Sources

  1. PrimaryCisco Secure FMC authentication bypass advisoryCiscoaccessed 2026-09-13

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.