Organizations Warned of Cisco Secure FMC Exploitation
Cisco and CISA warn that critical FMC authentication bypass CVE-2026-20079 is actively exploited; CISA added it to the KEV catalog with a September 12 deadline.
Cisco and CISA flagged active exploitation of CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center allowing remote, unauthenticated attackers to run malicious scripts and gain root access via crafted HTTP requests. Cisco patched the flaw in early March and added IoCs in late July, but confirmed active exploitation in its September 9 advisory; CISA added it to the KEV catalog requiring federal remediation by September 12. Talos identified three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including state-sponsored and financially motivated actors, and this is the third FMC vulnerability in KEV this year after CVE-2026-20316 and CVE-2026-20131.
- CVE-2026-20079 is a critical unauthenticated bypass enabling script execution and root access on Cisco Secure FMC.
- CISA added the flaw to its KEV catalog with a September 12 remediation deadline for federal agencies.
- Talos tracked three clusters: UAT-12197 (web shell, JAR credential theft), UAT-11823 (Sandworm, Cyclops Blink), and UAT-11988 (Qilin-linked, targeting CVE-2026-20316).
- CVE-2026-20316 and CVE-2026-20131 were also exploited as zero-days earlier in 2026.
- Defenses: apply patches and keep the FMC interface off the internet.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20079 | Authentication bypass to root access in Cisco Secure Firewall Management Center CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09. Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected. | 10.0 | 76% | KEV PoC ×2 |
| largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands) | |
| CVE-2026-20131 | Unauthenticated Java Deserialization RCE in Cisco FMC and SCC CVE-2026-20131 is a deserialization of untrusted data flaw (CWE-502) in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. An unauthenticated, remote attacker can trigger it by sending crafted serialized data to the exposed management interface. Successful exploitation allows the attacker to execute arbitrary Java code as root on the affected device, giving full control of the central platform that manages Cisco firewall policy. Any organization running FMC or managing firewalls through SCC is potentially affected; specific version ranges have not yet been published in the available data. The flaw was added to CISA KEV on 2026-03-19 with known ransomware use, and EPSS assigns a ~31% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. Do: Check Cisco's advisory for fixed releases and upgrade all FMC and SCC-managed deployments as soon as patched versions are identified, since version ranges are not yet in this data; until patched, restrict the FMC/SCC web-based management interface to trusted management networks or VPN access. Given the CISA KEV listing (added 2026-03-19) with known ransomware use, treat this as a high-priority patch and confirm whether BOD 22-01 remediation deadlines apply to your organization. | 10.0 | 33% | KEV ransomware |
| largetens of thousands of FMC/SCC management deployments (10k–100k systems), with a smaller subset of management interfaces internet-exposed | |
| CVE-2026-20316 | Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile). Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29. | 5.3 | 11% | KEV ransomware |
| largeplausibly tens of thousands of FMC deployments worldwide (no published install base) |
Full article448 words · extracted from securityweek.com · click to collapse
Cisco and the cybersecurity agency CISA on Wednesday flagged the exploitation of a Cisco Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year.
The security hole, tracked as CVE-2026-20079, is a critical authentication bypass issue that a remote, unauthenticated attacker can exploit to run malicious scripts on vulnerable devices, enabling root access to the underlying OS.
“This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device,” Cisco said in an advisory.
Cisco patched the vulnerability in early March, and in late July it updated the advisory for CVE-2026-20079 with indicators of compromise (IoCs). However, it did not explicitly warn about active exploitation at the time.
The tech giant updated its advisory again on September 9, saying that it became aware of the active exploitation of CVE-2026-20079 in August.
CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, instructing federal agencies to address it by September 12.
Advertisement. Scroll to continue reading.
Cisco FMC users can defend against attacks by installing the available patches. In addition, ensuring that the FMC interface cannot be accessed from the internet significantly reduces the risk of exploitation.
CVE-2026-20079 is the third FMC vulnerability added to CISA’s KEV list in 2026, after CVE-2026-20316 and CVE-2026-20131, which threat actors exploited as zero-days.
Attacks exploiting CVE-2026-20079 and CVE-2026-20316
Cisco’s Talos research and threat intelligence group reported on Wednesday that it’s aware of three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including state-sponsored threat actors and financially motivated groups.
One of the clusters, tracked by Talos as UAT-12197, exploited CVE-2026-20079 and deployed a web shell, which was used to deliver a malicious JAR file. This file then enabled the attacker to obtain user authentication data and credentials from the compromised system.
The second cluster is tracked as UAT-11823, which Talos has tied to the Russian APT known as Sandworm. This group exploited both FMC vulnerabilities and delivered the Cyclops Blink malware.
The Cyclops Blink sample observed by Talos in these attacks enables its operator to download/upload files, harvest credentials, execute arbitrary files and commands, and scan the network.
The third activity cluster is UAT-11988, believed to be connected to the Qilin ransomware. This threat actor exploited CVE-2026-20316 to gain access to targeted FMC devices, performing reconnaissance, stealing credentials, and creating a list of endpoints that can be targeted for encryption.
Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Related: MikroTik Patches Critical Flaws Chained to Hack Routers
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/organizations-warned-of-cisco-secure-fmc-exploitation/