Cisco Secure Firewall Management Center (FMC)

CVE-2026-20079: Cisco FMC authentication bypass gives root without a login

An unauthenticated attacker can bypass authentication in the FMC web interface and run scripts as root (CVSS 10.0). Exploited in the wild since at least August 2026, and a public proof of concept exists.

Published Updated

ExploitedYes, in CISA KEVAdded 9 Sept 2026
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 3.1 10
EPSS88%Chance of exploitation in 30 days
Public exploitYes
FixAvailable

Affected and fixed versions

Product / branchFixed in
Secure FMC 7.0 and earlier7.0.10 or later
Secure FMC 7.27.2.12 or later
Secure FMC 7.47.4.8 or later
Secure FMC 7.67.6.6 or later
Secure FMC 7.77.7.13 or later
Secure FMC 10.010.0.2 or later
Secure FMC 10.110.1.0 or later
Security Cloud Control (SCC) Firewall ManagementFixed by Cisco, no action needed
FTD, ASA, FDM, SCC (formerly Defense Orchestrator)Not affected

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

The web interface of Cisco Secure Firewall Management Center (FMC) can be tricked, with crafted HTTP requests, into skipping authentication. The attacker can then run scripts and get root on the FMC’s operating system, with no account. Cisco scores it 10.0 and attributes it to an improper system process created at boot time (CWE-288).

FMC manages your firewalls. Root on it means access to the configuration of every managed device, stored credentials and a foothold next to your Active Directory.

Cisco fixed this in March 2026 and learned of exploitation in August. A public proof of concept followed on August 20, and CISA added the CVE to KEV on September 9. Cisco Talos describes three clusters:

  • UAT-12197 exploits this CVE, drops a JSP web shell and a JAR command runner, and queries FMC’s database for user authentication data.
  • UAT-11823 (a Sandworm-overlapping group, per Talos) uses this CVE or static credentials. It replaces license.tmp with a reverse shell and installs a Cyclops Blink variant.
  • UAT-11988 looks like a Qilin ransomware affiliate. Talos says it logs in with static credentials (the related CVE-2026-20316), not this bug. It is included because it hits the same boxes.

CISA lists ransomware use of this CVE as “Unknown”.

Am I affected?

Yes, if you run on-premises Cisco Secure FMC on any version below the fixed releases in the table above. Cisco says it applies regardless of device configuration. The CVE record lists 7.0 to 7.7 and 10.0.0 to 10.0.1 as affected.

Cisco notes that the attack surface is smaller if the FMC management interface isn’t reachable from the internet. It isn’t a fix: an attacker with any network path to the web interface can use it.

Not affected: Firewall Threat Defense (FTD), ASA, Firewall Device Manager and Security Cloud Control. Cisco has already fixed the SaaS Security Cloud Control Firewall Management.

Use Cisco’s Software Checker to confirm your release.

What to do

  1. Upgrade FMC to a fixed hardening release (table above). Cisco’s hardening releases also fix other internally found bugs. There are no workarounds.
  2. Take the management interface off the internet. Restrict it to admin networks. This reduces exposure but does not replace the upgrade.
  3. Check for compromise before and after upgrading (Detection below). Cisco says its hot fixes and upgrades prevent future exploitation but may not clean an existing compromise.
  4. If you find signs of exploitation, call Cisco TAC straight away and follow their guidance. Treat FMC as fully compromised: assume managed-device configurations and credentials in FMC, and any AD service-account credentials it held, were read. Rotate them.
  5. Add Snort coverage. Cisco lists Snort rules 66075 to 66080 for this CVE. Talos lists 66883 for CVE-2026-20316 and 66960, 66961 for the malware.

CISA’s KEV entry also refers to BOD 26-04, including its forensics triage requirements, for federal agencies.

Detection

Cisco’s check. From expert mode, escalate to root and search the system log:

sudo su
zgrep "package_info.*license" /var/log/messages*

A line referencing /var/tmp/license.tmp, such as COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp, means the device may have been exploited.

From Talos’s analysis:

  • home.jsp or other unexpected JSP files in the Tomcat webroot, and cmd.jar run with /var/jre/bin/java -jar. The shell decodes a parameter named F6C1F0E7.
  • A FIFO at /tmp/f with nc or /bin/sh -i processes, and outbound connections to the C2 addresses above, notably port 3090.
  • Invocations of package_info.pl /var/tmp/license.tmp --lsm, and a license.tmp that is a Makeself package.
  • Unrecognised scripts under /etc/init.d/ (Cyclops Blink persistence).
  • Database queries through /var/sf/bin/OmniQuery.pl that read user authentication data.
  • A Python SOCKS5 proxy (socks5.py) and reverse-SSH tunnels from FMC, forwarding ports 389, 636, 88, 445, 135 and 5985.
  • Staged files on FMC pulled out with HTTP GET requests.
  • Static-credential logins to FMC (the UAT-11988 cluster).
  • Later, in the network: impacket, Invoke-TheHash and antivirus killers on endpoints, which come before Qilin ransomware.

Cisco says it learned of exploitation in August 2026, so search back at least to then, and further if your FMC was unpatched and reachable earlier.

Indicators of compromise

Hash types are not stated in the Talos article; the 64-character values are assumed to be SHA-256. Talos keeps the full lists on GitHub. The file paths are legitimate FMC files, so look at what ran and what changed, not just whether they exist.

The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2026-20079.txt

IndicatorTypeReported by
89.34.96[.]56IPUAT-11823, reverse shell and Cyclops Blink C2Cisco Talos
208.123.119[.]215IPUAT-11823, Netcat reverse shell C2 (port 3090)Cisco Talos
91.214.78[.]118IPUAT-11823, Netcat reverse shell C2Cisco Talos
104.218.165[.]253IPUAT-11823, scanner for CVE-2026-20079Cisco Talos
43.204.2[.]142IPUAT-11988, attacker IP used for intrusionsCisco Talos
b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77dSHA-256UAT-12197, home.jsp web shell (SHA-256)Cisco Talos
db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8eSHA-256UAT-12197, cmd.jar command executor (SHA-256)Cisco Talos
6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461SHA-256UAT-11823, Cyclops Blink malware (SHA-256)Cisco Talos
/var/tmp/license.tmpFile pathOverwritten with a malicious payload, then run as root through package_info.plCisco, Cisco Talos
/usr/local/sf/bin/package_info.plFile pathAbused to run license.tmp as rootCisco, Cisco Talos
home.jspFile pathJSP web shell in the Tomcat webrootCisco Talos
cmd.jarFile pathJAR command executor dropped by the web shellCisco Talos
/tmp/fFile pathFIFO used by the Netcat reverse shellCisco Talos

Cisco Talos IOC repository (September 2026).

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.