Cisco confirms exploited Secure FMC flaw
Cisco says attackers are exploiting a maximum-severity Secure FMC bug, but its own July advisory points to earlier activity.
Cisco has confirmed that attackers are exploiting a maximum-severity flaw in its Secure Firewall Management Center software, the central console that administrators use to configure and monitor Cisco's firewall estate. The vulnerability, tracked as CVE-2026-20079, carries a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to execute scripts and commands as root on vulnerable devices, according to the company's advisory.
The confirmation came on Wednesday, when Cisco updated the advisory to state that its Product Security Incident Response Team had become aware of active exploitation. The company's disclosure left several important questions unanswered, including when the attacks began, who was behind them, and what happened on compromised systems afterward.
What the flaw actually does
CVE-2026-20079 is an authentication bypass caused by an improper system process created at boot time, as Cisco's advisory describes it. An attacker can trigger the flaw by sending crafted HTTP requests to the web interface of an affected device.
If the requests succeed, the attacker can run scripts and commands on the device with root privileges, effectively taking full control of the management platform. Such a position would give an intruder a privileged foothold on the system that oversees an organization's firewall fleet.
Cisco first disclosed the bug in March. At that point, per its advisory, the company said it had no evidence of exploitation. As reported by BleepingComputer, Cisco said this week that it learned about active exploitation some months later.
The affected products, per the advisory, include Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management. Cisco says it has already patched the cloud-hosted Security Cloud Control service. For on-premises deployments, the company says there are no workarounds and recommends customers upgrade to the latest software release.
Federal deadline set for September 12
On the same day as Cisco's update, the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog. That listing requires Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
The KEV entry is based on Cisco's confirmation, and not on independent evidence published by CISA at the time of writing. Inclusion in the catalog does not mean CISA itself observed exploitation, only that it treats the vulnerability as one known to be exploited based on vendor reporting.
Evidence points to a July log entry
While Cisco says its security team became aware of active exploitation in August, indicators of compromise published in a July advisory update suggest the flaw may have been exploited earlier. The relevant log entry is dated July 23.
Cisco shared the log example on July 29, the same day it disclosed another Secure FMC vulnerability, tracked as CVE-2026-20316. That separate flaw was caused by static credentials for a low-privileged account. Cisco said at the time that CVE-2026-20316 had been actively exploited in attacks, and assigned it a High severity rating because the access could be combined with other Secure FMC vulnerabilities to elevate privileges.
As BleepingComputer reported at the time, Cisco also updated the CVE-2026-20079 advisory to include the same indicators as CVE-2026-20316, but did not then confirm the flaw was exploited. Cisco told administrators to search /var/log/messages for activity related to /var/tmp/license.tmp and shared the following example log entry:
Jul 23 16:16:33 firepower sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm
Cisco's advisory says that if this entry is found, the vulnerability "may have been exploited" on the examined Secure FMC device. The example is dated July 23, weeks before Cisco says PSIRT became aware of exploitation of CVE-2026-20079 in August.
Cisco also released the same Secure FMC hot fixes for both CVE-2026-20316 and CVE-2026-20079. The shared indicators, identical hot fixes, and the July 23 log entry together suggest both vulnerabilities may have been used in the same attacks, though Cisco has not confirmed that connection.
Cisco's answers left open questions
At the time of the July disclosure, BleepingComputer contacted Cisco to ask whether the two vulnerabilities were connected, whether CVE-2026-20079 had also been exploited, and whether Cisco intentionally added the shared indicator to both advisories. Cisco did not answer those questions directly.
Instead, a Cisco spokesperson provided the following statement to BleepingComputer: "On July 29, 2026, Cisco released software fixes to address vulnerabilities in Cisco Secure Firewall Management Center (FMC). Details are outlined in the security advisories (Static Credential vulnerability, Authentication Bypass vulnerability), and Cisco strongly recommends customers immediately apply the available fixes."
The spokesperson added: "Customers needing support should contact the Cisco Technical Assistance Center (TAC)."
Cisco's latest update now confirms that CVE-2026-20079 has been exploited, but does not clarify whether the July 23 activity included exploitation of both vulnerabilities. The company also has not said when the exploitation it is aware of began, nor has it described post-exploitation activity.
What administrators should check
For organizations running Cisco Secure FMC, the company's guidance is to search the /var/log/messages file for activity tied to /var/tmp/license.tmp. If the log entry is present, Cisco says the vulnerability "may have been exploited" on that device.
Cisco advises customers who discover the indicators of compromise to contact its TAC for support. It also warns that installing the hot fixes will prevent future exploitation but will not remediate devices that are already compromised. In other words, patching closes the door, but it does not remove an attacker who is already inside.
The company says there are no workarounds for the issue and recommends upgrading to the latest software release. The cloud-hosted Security Cloud Control service has already been patched, according to Cisco.
A patch that cannot undo a compromise
The distinction Cisco draws between preventing future exploitation and remediating an already-compromised appliance is central to how defenders should treat this incident. A management platform that has been taken over with root privileges cannot simply be patched back to a trusted state, because the patch does not address any persistence or secondary access the attacker may have established.
That leaves administrators with a hard choice: treat any device showing the indicators as compromised and rebuild or replace it, or accept the risk that the patch alone is insufficient. Cisco's own advisory language supports the more cautious reading, stating plainly that the hot fixes will not remediate devices already compromised.
The timeline adds a further complication. Cisco says it became aware of exploitation in August, but its own example log entry is dated July 23, and the same indicators and hot fixes covered both CVE-2026-20079 and CVE-2026-20316. Organizations that patched in July in response to the static-credential flaw may have addressed the same underlying access an attacker was already using, without knowing it.
Why it matters to defenders
For security teams, the most immediate problem is that the exploitation window may be longer than Cisco's August statement implies. If the July 23 log entry reflects real exploitation, then any Secure FMC appliance that was internet-facing or otherwise reachable between July 23 and the patch could have been compromised, and patching alone would not have undone that access. Cisco has not confirmed that reading, but it has not ruled it out either.
The practical consequence is that incident response, not just patch management, is the relevant discipline here. Administrators should search for the published indicator, and if it appears, treat the appliance as potentially compromised rather than merely unpatched. Cisco's own recommendation to contact TAC for support reflects that the situation calls for more than a software update.
The federal deadline of September 12, 2026 gives U.S. civilian agencies a fixed date to secure vulnerable systems, but it does not resolve the ambiguity about what happened in July. For everyone else running Secure FMC, the same ambiguity is the real story: the patch is available, the indicator is published, and the question of whether a device was already compromised is one only a careful review can answer.
Sources
- BleepingComputer Original source
Continue Reading
One Exploit Kit, Four Spy Groups, One Week
Proofpoint says China-aligned clusters rapidly adopted BlueMoon, a Chrome and Windows exploit chain that may have cost far less to build than expected.
Stolen AI Tokens Skirt Login Checks
Okta's review of a 7 GB infostealer dump found unexpired AI service tokens that can be replayed without a password or MFA.
Florida DMV Breach: 200K Records at Risk
ShinyHunters claims a Florida DMV breach, threatening to release 200,000 records by September 11.