Skip to content
feed: live
>_0dayNews
cisco
● Breaking

Cisco Confirms FMC CVSS 10 Auth Bypass Exploited

Cisco confirms CVE-2026-20079, CVSS 10.0 FMC auth bypass, is actively exploited. Unauthenticated attackers gain root OS access. CISA KEV deadline September 12.

Cisco Confirms FMC CVSS 10 Auth Bypass Exploited
Photo: Unknown / Wikimedia Commons · CC BY 2.5
fuseMarisol "Fuse" Delgado·Published ·2 min read

Cisco confirmed on September 9 that CVE-2026-20079, a maximum-severity authentication bypass in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management, is being actively exploited in attacks. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day and set a remediation deadline of September 12 for federal agencies.

That three-day window is a clear indicator of how seriously CISA is treating current exploitation activity.

What the flaw does

CVE-2026-20079 is an authentication bypass via an alternate path or channel. An unauthenticated, remote attacker can reach FMC or SCC through a path that skips normal authentication entirely, then execute scripts on the affected device with root privileges on the underlying operating system.

FMC is the management plane for Cisco Secure Firewall deployments. Root access on FMC means access to every firewall policy, network rule set, and traffic log the device administers. The CVSS 10.0 score reflects unauthenticated access, network-reachable attack surface, no user interaction required, and full OS-level compromise.

Details on affected versions and upgrade paths are in Cisco’s advisory (cisco-sa-onprem-fmc-authbypass-5JPp45V2).

CISA’s timeline and BOD 26-04

CISA’s September 9 KEV addition cites BOD 26-04, which layers forensic triage requirements onto the remediation timeline. Federal civilian executive branch (FCEB) agencies must apply mitigations by September 12 or, where patches are unavailable, discontinue use of the product.

For commercial operators: BOD 26-04 does not apply directly, but CVSS 10.0 with confirmed active exploitation is as direct a signal as this field produces.

What to do now

Patch. Check Cisco’s advisory for the upgrade path specific to your FMC version. Cisco has not documented a workaround that remediates the underlying bypass.

Where FMC’s management interface is internet-accessible, that is the most urgent case. Move to patch first, and if patching takes time, restrict management plane access to trusted hosts and management-only VLANs in the interim. Segmentation reduces the attack surface. It does not close the vulnerability.

Where the management interface is already isolated on a management VLAN behind jump hosts, the risk is lower but not zero. Lateral movement from an already-compromised host on that segment could reach FMC. Apply the patch on your next available maintenance window, not on the next quarter’s cycle.

Pattern

This is the second Cisco Secure FMC flaw to reach CISA’s KEV catalog in 2026. CVE-2026-20316, a hardcoded credential in FMC’s web interface, landed in the KEV catalog on July 29. The pattern is notable: FMC targets are attractive because compromising the management console gives an attacker visibility into the entire firewall policy rather than a single device.

Organizations running Cisco Secure Firewall infrastructure should have FMC’s management interface exposure documented and reviewed regularly. Two KEV entries in the same platform in six weeks is the kind of signal that warrants a dedicated assessment of management-plane access controls, not just a patch and move on.

For the full CVE entry with affected product details, see CVE-2026-20079.

Also relevant from the last 30 days of Cisco vulnerability activity: Cisco Nexus 9000 Critical RCE (CVE-2026-20212) and Cisco ASA/FTD VPN Flaw Exploited.

Related CVEs
  • [ CRITICAL ]CVE-2026-20079Cisco FMC Authentication Bypass Enables Root OS Access

Found this useful? Share it.