What happened and why it matters
Cisco announced that CVE‑2026‑20079 – a perfect‑score (10.0) authentication‑bypass vulnerability in its Secure Firewall Management Center (FMC) software – is being actively exploited.
The US CISA promptly placed the flaw in its Known Exploited Vulnerabilities catalog, giving federal agencies a hard deadline of 12 Sep 2026 to remediate.
Technical specifics
The bug stems from an improper system process created at boot. An unauthenticated attacker can send a crafted HTTP request to the FMC web interface, slip past login, and run arbitrary commands as root.
There is no workaround; the only defense is to apply Cisco’s hot‑fix released on 29 Jul 2026. The patch covers both the on‑premise Secure FMC product and the cloud‑hosted Security Cloud Control service.
Who is affected
Any organization running Cisco Secure Firewall Management Center software or the Cisco Security Cloud Control Firewall Management service is in scope.
Customers who have not yet applied the July hot‑fix remain exposed to remote code execution with full system privileges.
Indicators of compromise
Cisco told admins to hunt for entries in /var/log/messages referencing /var/tmp/license.tmp. A sample log dated 23 Jul 2026 was shared as a reference point.
Unconfirmed: Some analysts suspect the July 23 log could also involve CVE‑2026‑20316, another high‑severity flaw disclosed the same day, but Cisco has not validated that link.
What you should do now
- Verify your FMC version and confirm whether the July 29 hot‑fix is installed.
- If you run the cloud‑hosted Security Cloud Control service, ensure the service‑side patch has been applied.
- Search
/var/log/messagesfor the/var/tmp/license.tmpstring; any matches warrant immediate TAC contact. - Document findings and report to your incident‑response team – the hot‑fix stops future attacks but does not cleanse already compromised hosts.
- Track the CISA KEV deadline and prioritize remediation to stay compliant.
