Cisco Secure Firewall Management Center (FMC)
CVE-2026-20079: Cisco FMC authentication bypass gives root without a login
An unauthenticated attacker can bypass authentication in the FMC web interface and run scripts as root (CVSS 10.0). Exploited in the wild since at least August 2026, and a public proof of concept exists.
Published Updated
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Secure FMC 7.0 and earlier | 7.0.10 or later |
| Secure FMC 7.2 | 7.2.12 or later |
| Secure FMC 7.4 | 7.4.8 or later |
| Secure FMC 7.6 | 7.6.6 or later |
| Secure FMC 7.7 | 7.7.13 or later |
| Secure FMC 10.0 | 10.0.2 or later |
| Secure FMC 10.1 | 10.1.0 or later |
| Security Cloud Control (SCC) Firewall Management | Fixed by Cisco, no action needed |
| FTD, ASA, FDM, SCC (formerly Defense Orchestrator) | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
The web interface of Cisco Secure Firewall Management Center (FMC) can be tricked, with crafted HTTP requests, into skipping authentication. The attacker can then run scripts and get root on the FMC’s operating system, with no account. Cisco scores it 10.0 and attributes it to an improper system process created at boot time (CWE-288).
FMC manages your firewalls. Root on it means access to the configuration of every managed device, stored credentials and a foothold next to your Active Directory.
Cisco fixed this in March 2026 and learned of exploitation in August. A public proof of concept followed on August 20, and CISA added the CVE to KEV on September 9. Cisco Talos describes three clusters:
- UAT-12197 exploits this CVE, drops a JSP web shell and a JAR command runner, and queries FMC’s database for user authentication data.
- UAT-11823 (a Sandworm-overlapping group, per Talos) uses this CVE or static credentials. It replaces
license.tmpwith a reverse shell and installs a Cyclops Blink variant. - UAT-11988 looks like a Qilin ransomware affiliate. Talos says it logs in with static credentials (the related CVE-2026-20316), not this bug. It is included because it hits the same boxes.
CISA lists ransomware use of this CVE as “Unknown”.
Am I affected?
Yes, if you run on-premises Cisco Secure FMC on any version below the fixed releases in the table above. Cisco says it applies regardless of device configuration. The CVE record lists 7.0 to 7.7 and 10.0.0 to 10.0.1 as affected.
Cisco notes that the attack surface is smaller if the FMC management interface isn’t reachable from the internet. It isn’t a fix: an attacker with any network path to the web interface can use it.
Not affected: Firewall Threat Defense (FTD), ASA, Firewall Device Manager and Security Cloud Control. Cisco has already fixed the SaaS Security Cloud Control Firewall Management.
Use Cisco’s Software Checker to confirm your release.
What to do
- Upgrade FMC to a fixed hardening release (table above). Cisco’s hardening releases also fix other internally found bugs. There are no workarounds.
- Take the management interface off the internet. Restrict it to admin networks. This reduces exposure but does not replace the upgrade.
- Check for compromise before and after upgrading (Detection below). Cisco says its hot fixes and upgrades prevent future exploitation but may not clean an existing compromise.
- If you find signs of exploitation, call Cisco TAC straight away and follow their guidance. Treat FMC as fully compromised: assume managed-device configurations and credentials in FMC, and any AD service-account credentials it held, were read. Rotate them.
- Add Snort coverage. Cisco lists Snort rules 66075 to 66080 for this CVE. Talos lists 66883 for CVE-2026-20316 and 66960, 66961 for the malware.
CISA’s KEV entry also refers to BOD 26-04, including its forensics triage requirements, for federal agencies.
Detection
Cisco’s check. From expert mode, escalate to root and search the system log:
sudo su
zgrep "package_info.*license" /var/log/messages*
A line referencing /var/tmp/license.tmp, such as COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp, means the device may have been exploited.
From Talos’s analysis:
home.jspor other unexpected JSP files in the Tomcat webroot, andcmd.jarrun with/var/jre/bin/java -jar. The shell decodes a parameter namedF6C1F0E7.- A FIFO at
/tmp/fwithncor/bin/sh -iprocesses, and outbound connections to the C2 addresses above, notably port 3090. - Invocations of
package_info.pl /var/tmp/license.tmp --lsm, and alicense.tmpthat is a Makeself package. - Unrecognised scripts under
/etc/init.d/(Cyclops Blink persistence). - Database queries through
/var/sf/bin/OmniQuery.plthat read user authentication data. - A Python SOCKS5 proxy (
socks5.py) and reverse-SSH tunnels from FMC, forwarding ports 389, 636, 88, 445, 135 and 5985. - Staged files on FMC pulled out with HTTP GET requests.
- Static-credential logins to FMC (the UAT-11988 cluster).
- Later, in the network: impacket, Invoke-TheHash and antivirus killers on endpoints, which come before Qilin ransomware.
Cisco says it learned of exploitation in August 2026, so search back at least to then, and further if your FMC was unpatched and reachable earlier.
Indicators of compromise
Hash types are not stated in the Talos article; the 64-character values are assumed to be SHA-256. Talos keeps the full lists on GitHub. The file paths are legitimate FMC files, so look at what ran and what changed, not just whether they exist.
The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2026-20079.txt
| Indicator | Type | Reported by |
|---|---|---|
| 89.34.96[.]56 | IPUAT-11823, reverse shell and Cyclops Blink C2 | Cisco Talos |
| 208.123.119[.]215 | IPUAT-11823, Netcat reverse shell C2 (port 3090) | Cisco Talos |
| 91.214.78[.]118 | IPUAT-11823, Netcat reverse shell C2 | Cisco Talos |
| 104.218.165[.]253 | IPUAT-11823, scanner for CVE-2026-20079 | Cisco Talos |
| 43.204.2[.]142 | IPUAT-11988, attacker IP used for intrusions | Cisco Talos |
| b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d | SHA-256UAT-12197, home.jsp web shell (SHA-256) | Cisco Talos |
| db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e | SHA-256UAT-12197, cmd.jar command executor (SHA-256) | Cisco Talos |
| 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 | SHA-256UAT-11823, Cyclops Blink malware (SHA-256) | Cisco Talos |
| /var/tmp/license.tmp | File pathOverwritten with a malicious payload, then run as root through package_info.pl | Cisco, Cisco Talos |
| /usr/local/sf/bin/package_info.pl | File pathAbused to run license.tmp as root | Cisco, Cisco Talos |
| home.jsp | File pathJSP web shell in the Tomcat webroot | Cisco Talos |
| cmd.jar | File pathJAR command executor dropped by the web shell | Cisco Talos |
| /tmp/f | File pathFIFO used by the Netcat reverse shell | Cisco Talos |
Sources
Page changelog
- Full analysis published.
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.