Security Advisory
CVE-2026-20079: CISA Warns of Active Cisco Firewall Manager Attacks
CISA and Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 bypass in Cisco Secure Firewall Management Center.
Cisco disclosed CVE-2026-20079 on March 4, 2026 as part of a routine bundled security advisory for its Secure Firewall product line. On September 9, 2026, Cisco updated that advisory to state that its Product Security Incident Response Team "became aware of active exploitation of this vulnerability" in August 2026, and the same day Cisco Talos published a technical writeup detailing three separate intrusion clusters already active against real organizations: one that exploited CVE-2026-20079 directly, a second that Talos assessed with high confidence as an advanced, state-sponsored actor using either CVE-2026-20079 or static credentials, and a third that Talos assessed as a ransomware operator that used a related, static-credential flaw rather than CVE-2026-20079 itself. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog that same day and gave federal civilian agencies until September 12, 2026 to remediate under Binding Operational Directive 26-04, according to Cisco's security advisory, Cisco Talos, and CISA.
Secure Firewall Management Center (FMC) is the centralized console administrators use to configure policy, VPN access, and logging across an organization's fleet of Cisco firewalls. An unauthenticated attacker who compromises that console does not need to breach a single firewall individually; they inherit root-level control of the interface that manages every policy across the fleet at once.
What the Advisory Covers, and What It Does Not
CVE-2026-20079 carries a maximum CVSS v3.1 base score of 10.0. Cisco's advisory attributes the flaw to an improperly created system process at boot time in the FMC web interface: a remote attacker can send crafted HTTP requests to that process to bypass authentication and execute scripts or commands with root privileges. Cisco's advisory lists the vulnerability as affecting "Cisco Secure FMC Software and Cisco Security Cloud Control (SCC) Firewall Management, regardless of device configuration," but the two are not affected the same way. On-premises Secure FMC Software is what customers must patch themselves; Cisco has published hot fixes only for the 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 release trains, and states plainly that "there are no workarounds that address this vulnerability." SCC Firewall Management, by contrast, is a SaaS-delivered offering: Cisco's advisory states that "the fix for this vulnerability has been deployed to Cisco SCC Firewall Management environments" and that "no user action is required" for that service. Secure Firewall Device Manager, ASA Software, FTD Software, and SCC's separate Defense Orchestrator service are not affected.
Cisco's advisory also draws a distinction worth repeating exactly: the published hot fixes "are for preventing future exploitation only and may not address existing compromise." Cisco directs any organization that suspects it was already compromised to contact the Cisco Technical Assistance Center (TAC) for recovery assistance rather than treating the hot fix alone as remediation.
Active Exploitation, Per Cisco Talos
Cisco Talos's September 9 writeup ties active exploitation to at least three distinct intrusion clusters, and attributes a different initial-access path to each. One, tracked as UAT-12197, exploited CVE-2026-20079 itself, then deployed JSP-based web shells and a Java-based command executor Talos calls cmd.jar to extract database credentials from compromised FMC instances. A second, UAT-11823, is one Talos assessed with high confidence as an advanced, state-sponsored actor whose tooling overlaps with Sandworm, a threat actor publicly linked to Russian military intelligence; Talos says this cluster gained initial access "by either exploiting CVE-2026-20079 or via static credentials," then deployed a variant of the Cyclops Blink modular implant, which Talos reported supports DNS-over-HTTPS command and control, file administration, credential harvesting, arbitrary command execution, network scanning, and packet sniffing, alongside SOCKS5 proxy and reverse SSH tunneling tools. The third cluster, a ransomware operator Talos tracks as UAT-11988, gained access a different way: Talos says it logged into an FMC device using static credentials tied to a separate, lower-severity flaw, CVE-2026-20316 (CVSS 5.3), then deployed antivirus-killing tools and, Talos states, "ultimately the Qilin ransomware family" itself, not merely tooling staged for a future attack.
Key Recommendations
Start with an honest inventory. On-premises Secure FMC is what needs your attention; if your organization only uses cloud-delivered SCC Firewall Management, Cisco states the fix is already applied and no action is required on your end. Confirm which one you, or your managed service provider, actually operate.
If you run on-premises Secure FMC, apply the hot fix on an emergency basis rather than a routine maintenance window; Cisco has confirmed there is no workaround. If your release is not one of the six hot-fixed trains, including an older or end-of-life release, use Cisco's Software Checker tool to confirm your exposure and the required upgrade path.
If your FMC instance was internet-reachable at any point since August 2026 and was not already on a hot-fixed build, treat this as a possible compromise warranting investigation, not only a missing patch. Check for the indicators Talos published (unfamiliar JSP files or web shells, a file named cmd.jar, unexpected DNS-over-HTTPS traffic, unrecognized SOCKS5 proxy or reverse SSH activity), and remember that applying the hot fix alone does not remove an existing intrusion; if you suspect compromise, contact Cisco TAC for recovery assistance.
Confirm your FMC management interface is not reachable from the open internet, and extend the same questions to any vendor or managed service provider that operates firewall infrastructure on your behalf.
For healthcare and financial-services organizations, a firewall management console governs the segmentation and access controls that a HIPAA Security Rule or FTC Safeguards Rule risk analysis is required to evaluate. HHS Office for Civil Rights guidance is explicit that identifying and remediating known, actively exploited vulnerabilities in routers and firewalls is part of the HIPAA risk analysis and technical-safeguards obligation, and the FTC Safeguards Rule imposes a comparable vulnerability-monitoring expectation under 16 CFR 314.4(d)(2) on nonbanking financial institutions, though institutions maintaining customer information on fewer than 5,000 consumers are exempt from that specific written risk-assessment and periodic vulnerability-testing requirement. CISA's September 12 remediation window applies specifically to federal civilian agencies; it is not itself a compliance deadline, but the underlying, publicly confirmed exploitation is exactly the kind of known, actively exploited vulnerability those risk-analysis obligations already require you to identify and remediate on an ongoing basis.
For organizations that operate Cisco firewall infrastructure or serve clients who do, we recommend an immediate version check against Cisco's advisory. Cyber One Solutions can help through our IT and security assessments, which inventory exposed management infrastructure like this one, and our managed cybersecurity service, which keeps perimeter and management systems patched and monitored on a documented schedule.
Sources
- Cisco Security Advisory: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
- Cisco Talos: Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
- CISA Known Exploited Vulnerabilities Catalog
- CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog
- Help Net Security: Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
- HHS OCR: January 2026 Cybersecurity Newsletter
- Federal Trade Commission: FTC Safeguards Rule, What Your Business Needs to Know
