HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Authentication Bypass in Cisco Secure FMC (CVE‑2026‑20079) Actively Exploited

Cisco Secure FMC software contains a CVSS 10.0 authentication‑bypass vulnerability (CVE‑2026‑20079) that is being actively exploited. The flaw lets unauthenticated attackers gain root, highlighting the need for verifiable access‑control controls and audit‑ready patch evidence.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
5 recommended
📰
Source
bleepingcomputer.com

Critical Authentication Bypass in Cisco Secure FMC (CVE‑2026‑20079) Actively Exploited

What It Is – Cisco Secure Firewall Management Center (FMC) contains a maximum‑severity authentication‑bypass flaw (CVE‑2026‑20079) that lets unauthenticated remote attackers execute commands as root.

Exploitability – The vulnerability scores a CVSS 10.0. Cisco’s PSIRT observed active exploitation in August 2026, and CISA has listed it in the KEV catalog, mandating remediation for federal agencies.

Affected Products – Cisco Secure FMC software (on‑prem) and Cisco Security Cloud Control Firewall Management (cloud‑hosted).

Why It Matters for Trust & Control Assurance

  • Access‑control integrity – The flaw demonstrates that authentication mechanisms can be bypassed, violating the control objective of ensuring only authorized users can access privileged functions.
  • Continuous evidence – Detecting the exploit requires log‑monitoring for specific IOC entries, underscoring the need for auditable, real‑time evidence of control effectiveness.
  • Defensible audit trail – Organizations must prove they have patched or mitigated the flaw; documented patch status and log reviews become critical evidence during compliance assessments.

Recommended Actions

  1. Immediately upgrade all Secure FMC instances to the latest patched release.
  2. Verify patch deployment via automated inventory tools and retain version evidence.
  3. Search /var/log/messages for the IOC pattern (/var/tmp/license.tmp) and investigate any matches.
  4. Harden the management interface: restrict network access, enforce MFA for admin accounts, and enable strict logging.
  5. Incorporate the patch status into your continuous control‑monitoring dashboard to maintain audit‑ready evidence.

Source: BleepingComputer – Cisco confirms CVE‑2026‑20079 Secure FMC flaw exploited in attacks

📰 Original Source
https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →