CVE-2026-20079 – Critical Authentication Bypass in Cisco Secure Firewall Management Center

  • Critical CVSS 10.0 auth bypass in Cisco Secure FMC
  • Active exploitation by nation-state and ransomware actors
  • CISA KEV listed; no workaround — patch immediately
  • Leads to full root control, credential theft, and ransomware deployment
  • Affected versions: 7.0.0 through 7.4.1.1 and 10.0.0/10.0.1

CVE-2026-20079 is a Critical authentication bypass in Cisco Secure Firewall Management Center (CVSS 10.0) allowing unauthenticated remote attackers to execute scripts and gain root access. Cisco confirmed active exploitation by nation-state and ransomware actors, with CISA adding it to the KEV catalog on 2026-09-09.

Overview

The vulnerability resides in the web interface of Cisco Secure FMC due to an improper boot-time process. Attackers send crafted HTTP requests to bypass authentication and execute scripts that yield root on the underlying OS. Cisco Talos tracked three intrusion clusters—web shells/JAR execution, Cyclops Blink deployment, and Qilin ransomware—demonstrating the risk of compromising security infrastructure.

Technical Details

  • CVSS 10.0 — AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • CWE-288: Authentication Bypass Using an Alternate Path or Channel
  • Vector: unauthenticated, remote, crafted HTTP requests
  • Impact: script execution, root access, full OS compromise
  • Related: CVE-2026-20316 (static credentials, CVSS 5.3) also actively exploited

Severity & Impact

Critical with CVSS 10.0. FMC management-plane compromise cascades to firewall enforcement. Observed post-exploitation includes credential harvesting, AD/MySQL theft, SOCKS5/reverse-SSH tunnels, and ransomware deployment. Mention activity spiked to 74 reports in a single day after CISA KEV addition. For key indicators, exploit activity over time, and detailed signal data, see the CVE page.

Affected Products

Cisco Secure Firewall Management Center versions 7.0.0–7.4.1.1 and 10.0.0–10.0.1. For the full list of affected products and versions, see CVE page.

Actionable Insights

  • Active exploitation observed before and after disclosure; surge in Sept 2026.
  • Intrusion clusters use distinct toolsets—monitor for web shells, Cyclops Blink, and Qilin TTPs.
  • No workaround exists for CVE-2026-20079—assume compromise if exposed.
  • Hunt for Impacket, Invoke-TheHash, and anomalous FMC HTTP requests.

Remediation & Mitigation

  1. Apply Cisco hotfixes immediately per the vendor advisory.
  2. Validate FMC integrity; check for unauthorized web shells or JAR files.
  3. Hunt for Cyclops Blink and Qilin ransomware indicators on managed endpoints.
  4. Restrict FMC internet exposure and enforce MFA on management interfaces.
  5. Follow CISA BOD 26-04 guidance for prioritization and forensics triage.

References

  • Cisco PSIRT Advisory:
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
    
  • Cisco Talos Research:
    https://blog.talosintelligence.com/fmc-ongoing-exploitation/
    
  • CISA Known Exploited Vulnerabilities:
    https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20079
    
  • Live signal data:
    https://vulnsocial.com/cve/CVE-2026-20079
    

Bottom line: CVE-2026-20079 is a Critical auth bypass in Cisco Secure FMC with active exploitation, CVSS 10.0, and CISA KEV status. Apply vendor hotfixes immediately and treat any exposed FMC as potentially compromised.

#CVE #CVE202620079 #Critical #RCE #CISAKEV #Cisco #FMC #CyberSecurity