Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-20079 2026-09-09

Cisco FMC Auth Bypass (CVE-2026-20079): Unauthenticated Root, CVSS 10.0, and Already Under Attack

"CISA added CVE-2026-20079 to the Known Exploited Vulnerabilities catalog on 2026-09-09, giving federal agencies until 2026-09-12 to remediate a maximum-severity authentication bypass that hands unauthenticated attackers…"

CISA added CVE-2026-20079 to the Known Exploited Vulnerabilities catalog on 2026-09-09, giving federal agencies until 2026-09-12 to remediate a maximum-severity authentication bypass that hands unauthenticated attackers root on Cisco Secure Firewall Management Center.

What Is It

A flaw in the web interface of Cisco Secure Firewall Management Center (FMC) Software lets an unauthenticated, remote attacker bypass authentication and execute script files on the device, obtaining root access to the underlying operating system. The root cause is an improper system process created at boot time. Exploitation is done by sending crafted HTTP requests to an affected device; a successful exploit allows the attacker to run a variety of scripts and commands with root privileges.

CISA classifies it as CWE-288, authentication bypass using an alternate path or channel. NVD scores it CVSS 10.0 (CRITICAL): CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Network-reachable, low complexity, no privileges, no user interaction, and a scope change.

Why It Matters

CISA's KEV listing confirms active exploitation in the wild. Cisco Talos has published research on ongoing exploitation of FMC. The KEV entry also flags forensic triage requirements, meaning affected agencies must preserve and analyze evidence rather than simply patch and move on. Known ransomware campaign use is listed as Unknown.

The target is the management plane itself. FMC administers fleets of Cisco firewalls, so root on FMC means control over the policy that protects everything downstream.

What's Vulnerable

Per CISA, both Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management are affected. NVD lists affected FMC versions spanning the 7.0.x, 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.6.x, and 7.7.x branches, as well as 10.0.0 and 10.0.1; including recent releases such as 7.0.9, 7.2.11, 7.4.7, 7.6.5, and 7.7.12.

Patch Status

CISA's required action: apply mitigations per Cisco's instructions, in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, follow the applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Due date: 2026-09-12.

Sources