Cybersecurity

Cisco Confirms Exploitation of Critical Secure FMC Vulnerability and Urges Customers to Update Immediately

Cisco confirmed that a 10.0-severity authentication bypass vulnerability in Secure Firewall Management Center is being actively exploited, after the company said in March that it had no evidence of exploitation. No workaround is available, and installing the fixes does not remediate devices that have already been compromised.

2026-09-09
3 min read
8 views
فريق تحرير certi.news
Cisco Confirms Exploitation of Critical Secure FMC Vulnerability and Urges Customers to Update Immediately

Cisco confirmed that a critical security vulnerability, CVE-2026-20079, in Cisco Secure Firewall Management Center (FMC) software is being exploited in real-world attacks. The vulnerability has the maximum CVSS score of 10.0 and allows a remote, unauthenticated attacker to bypass authentication and execute scripts and commands with root privileges on affected devices.

Cisco’s security incident response team, known as PSIRT, updated the vulnerability advisory on Wednesday, explaining that it learned of active exploitation in August 2026. The company first disclosed the vulnerability in March, but said at the time that it had no evidence that it was being used in attacks. Cisco did not specify when the attacks began or who was behind them, nor did it disclose details about activity that occurred after the compromise.

How Can the Vulnerability Be Exploited?

The issue results from the improper creation of a system process during device startup. An attacker can exploit it by sending specially crafted HTTP requests to the device’s web interface. If the attack succeeds, the unauthenticated attacker gains the ability to execute scripts and commands with root privileges.

The affected products include Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management. Cisco says it has fixed the cloud-hosted Security Cloud Control service, but recommends that on-premises software customers upgrade to the latest available version, confirming that no workaround exists for the vulnerability.

Indicators Point to Earlier Activity

Although Cisco linked its awareness of active exploitation to August, indicators of compromise published in an earlier update in July suggest that the activity may have begun before then. On July 29, the company disclosed another vulnerability in Secure FMC, CVE-2026-20316, caused by hard-coded credentials for a low-privilege account, and said it had been exploited in attacks.

The updates for the two vulnerabilities included identical indicators and identical urgent remediation guidance. Cisco also asked administrators to search /var/log/messages for activity associated with the path /var/tmp/license.tmp, including a log dated July 23 that records execution of the command /usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm with root privileges. The company says finding this log may indicate that the device was exploited, but it did not clarify whether the same activity involved both vulnerabilities together.

What Does This Mean for Administrators?

The U.S. Cybersecurity and Infrastructure Security Agency, CISA, added CVE-2026-20079 to its Known Exploited Vulnerabilities Catalog and required U.S. federal civilian executive-branch agencies to secure affected systems before September 12, 2026.

The practical priority is not limited to installing the fixes. Cisco warns that the update prevents future exploitation but does not remediate a device that has already been compromised. Customers who find indicators of compromise should therefore contact the Technical Assistance Center, TAC, while questions remain about the timing of the attacks, the perpetrator, and whether exploitation of the two vulnerabilities occurred as part of the same campaign.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news