TechNewsReel
Live

Cisco Confirms Active Exploitation of Critical Root-Level FMC Auth Bypass

A CVSS 10.0 vulnerability in Secure Firewall Management Center allows remote attackers to gain full root privileges.

TechNewsReel Newsroom · September 9, 2026

Cisco has confirmed that a critical authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software is being actively exploited. The flaw, tracked as CVE-2026-20079, allows unauthenticated remote actors to bypass security checks and execute commands with full root privileges.

The vulnerability carries a maximum CVSS v3.1 score of 10.0, the highest possible severity rating. The root cause is an improper system process created during the boot sequence. Attackers can trigger this flaw by sending specially crafted HTTP requests to the appliance's web interface, granting them immediate administrative control over the system.

A Pattern of Exploitation

Cisco first disclosed the vulnerability in March 2026, though it initially reported no evidence of active exploitation. The situation evolved in July 2026 when the company disclosed a separate flaw, CVE-2026-20316, which involved the use of static credentials.

Security analysis indicates that these two vulnerabilities are closely linked. Both flaws share the same indicators of compromise (IOCs) and are addressed by the same set of hotfixes. Evidence suggests that attackers may be using these vulnerabilities in tandem, chaining the static credential flaw with the authentication bypass to elevate their privileges and secure root-level access to the device.

The Risk to the Management Plane

This vulnerability is particularly dangerous because it targets the management plane of the firewall. In a standard security architecture, the management plane is the central nervous system used by administrators to configure security policies and monitor network health.

By gaining root-level access to the underlying operating system of the security appliance, an attacker effectively neutralizes the firewall's primary purpose. Once inside, a threat actor can manipulate security policies to allow malicious traffic, monitor sensitive network data, or use the compromised appliance as a trusted pivot point to launch deeper attacks into the internal network.

Current Status and Mitigation

Cisco's Product Security Incident Response Team (PSIRT) became aware of the active exploitation of CVE-2026-20079 in August 2026. While the related static credential flaw (CVE-2026-20316) was added to CISA's Known Exploited Vulnerabilities (KEV) catalog in July, the overall risk profile for FMC users remains critical due to the chaining of these exploits.

Organizations using Secure FMC are urged to apply the latest hotfixes immediately. Security teams should prioritize auditing their management interfaces for unauthorized access and reviewing logs for the specific IOCs associated with these two vulnerabilities to determine if their environment has already been compromised.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.