Critical Authentication Bypass in Cisco Secure FMC (CVE‑2026‑20079) Actively Exploited
What It Is – Cisco Secure Firewall Management Center (FMC) contains a maximum‑severity authentication‑bypass flaw (CVE‑2026‑20079) that lets unauthenticated remote attackers execute commands as root.
Exploitability – The vulnerability scores a CVSS 10.0. Cisco’s PSIRT observed active exploitation in August 2026, and CISA has listed it in the KEV catalog, mandating remediation for federal agencies.
Affected Products – Cisco Secure FMC software (on‑prem) and Cisco Security Cloud Control Firewall Management (cloud‑hosted).
Why It Matters for Trust & Control Assurance
- Access‑control integrity – The flaw demonstrates that authentication mechanisms can be bypassed, violating the control objective of ensuring only authorized users can access privileged functions.
- Continuous evidence – Detecting the exploit requires log‑monitoring for specific IOC entries, underscoring the need for auditable, real‑time evidence of control effectiveness.
- Defensible audit trail – Organizations must prove they have patched or mitigated the flaw; documented patch status and log reviews become critical evidence during compliance assessments.
Recommended Actions
- Immediately upgrade all Secure FMC instances to the latest patched release.
- Verify patch deployment via automated inventory tools and retain version evidence.
- Search
/var/log/messagesfor the IOC pattern (/var/tmp/license.tmp) and investigate any matches. - Harden the management interface: restrict network access, enforce MFA for admin accounts, and enable strict logging.
- Incorporate the patch status into your continuous control‑monitoring dashboard to maintain audit‑ready evidence.
Source: BleepingComputer – Cisco confirms CVE‑2026‑20079 Secure FMC flaw exploited in attacks