Cisco has confirmed that a maximum severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated remote attackers to bypass authentication and execute scripts and commands as root on affected devices. “In August 2026, Cisco PSIRT became aware of active exploitation of this vulnerability,” Cisco said in a statement Wednesday. Cisco did not disclose when the attacks began, who was behind them, or what activity was observed after the exploitation. Cisco first disclosed CVE-2026-20079 in March, when the company said it had no evidence that the vulnerability was used in attacks. The vulnerability is caused by an incorrect system process created during boot and can be exploited by sending crafted HTTP requests to the web interface of an affected device. A successful attack could allow an unauthenticated attacker to execute scripts and commands on the device with root privileges. The vulnerability affects Cisco Secure FMC software and Cisco Security Cloud Control firewall management. Cisco says it has already fixed its Security Cloud Control service. Cisco says there are no workarounds and recommends that customers update to the latest version of the software. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) today added CVE-2026-20079 to its catalog of known exploitable vulnerabilities (KEVs), directing federal civil enforcement agencies to secure vulnerable systems by September 12, 2026. Evidence of exploitation emerged in July While Cisco says its security team became aware of active exploitation of CVE-2026-20079 in August, IOCs published in a July advisory update suggest the vulnerability may have been exploited earlier. On July 29, Cisco disclosed another Secure FMC vulnerability, tracked as CVE-2026-20316, caused by static credentials for a low-privileged account. At the time, Cisco said that CVE-2026-20316 was actively used in attacks and assigned it a high severity level because access could be combined with other Secure FMC vulnerabilities to escalate privileges. As BleepingComputer reported at the time, Cisco also updated the advisory for CVE-2026-20079 to include the same indicators as CVE-2026-20316, but did not confirm that the vulnerability had been exploited. Cisco advised administrators to look in /var/log/messages for activity related to /var/tmp/license.tmp and shared the following example log entry: Jul 23 16:16:33 firepower sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm Cisco says that if this entry is found, the vulnerability “may have been exploited” on a trusted Secure FMC device. The example log entry is dated July 23, several weeks before Cisco reported that PSIRT learned of CVE-2026-20079 in August. Cisco has also released identical Secure FMC patches for CVE-2026-20316 and CVE-2026-20079. At the time, BleepingComputer contacted Cisco to see if the two vulnerabilities were related, if CVE-2026-20079 was also exploited, and if Cisco intentionally added a common indicator to both advisories. Cisco did not respond to questions directly, but instead shared the following statement: “On July 29, 2026, Cisco released software patches to address vulnerabilities in the Cisco Secure Firewall Management Center (FMC). Details are outlined in the security advisory (Static Credentials Vulnerability, Authentication Bypass Vulnerability) and Cisco strongly encourages customers to immediately apply available patches,” a Cisco spokesperson told BleepingComputer. “Customers requiring support should contact the Cisco Technical Assistance Center (TAC).” Cisco’s latest update now confirms that CVE-2026-20079 was exploited, but does not clarify whether the activity on July 23 included exploitation of both vulnerabilities. However, identical IOCs for both vulnerabilities, identical July patches, and a log entry dated July 23 suggest that both vulnerabilities may have been used in the same attacks. Cisco advises customers who detect signs of compromise to contact the Technical Assistance Center for support, warning that patching will prevent future exploitation of the vulnerabilities but will not fix devices that have already been compromised. General prevention scores may obscure what happens after initial access. Once attackers use valid credentials, prevention effectiveness drops dramatically. The Blue Report 2026 measures security technique by technique based on 338 million simulations run in customer production environments. Get report Post navigation Apple shares details about restrictions and terms of use of Apple Intelligence Xabi Alonso corrects Chelsea’s big mistake and key talking points after Leeds win