Cisco warns about active abuse of CVE-2026-20079 in Cisco Secure Firewall Management Center (FMC).

The vulnerability has CVSS 10.0. An unauthenticated external attacker can bypass authentication via the web interface, run scripts and commands and eventually root access gain access to the underlying system.

Cisco has the security advisory on 9 September 2026 updated confirming that the vulnerability is actually abused.

You using Cisco Secure FMC? Then check instant patch status and possible compromise.

Why is this vulnerability serious?

Cisco Secure Firewall Management Center is used to centrally manage Cisco firewall environments.

Cisco Talos describes multiple attacks on FMC systems, including observed:

  • webshells;
  • credimental theft;
  • system and network data exfil;
  • reverse shells and tunneling;
  • Reconnaissance in environments.

Talos describes three different clusters of post-compromise activity using CVE-2026-20079 and/or CVE-2026-20316.

One cluster saw malware overlap with tooling previously linked to Sandworm. Another cluster showed behaviour of a ransomware operator and eventually led to deployment of Qilin ransomware at selected endpoints.

Talos describes different attack chains. Therefore, it cannot be concluded that any observed attack or the entire Qilin campaign was carried out exclusively via CVE-2026-20079.

What systems have been affected?

CVE-2026-20079 Cisco Secure Firewall Management Center Software.

Cisco Security Cloud Control Firewall Management is a SaaS service that Cisco itself updated; Cisco says there's no need for customer action.

Cisco ASA and Secure Firewall Threat Defense (FTD) are not themselves vulnerable to this specific CVE.

Use the current Cisco Software Checker or advisory to determine exactly which FMC release is vulnerable.

What do you have to do now?

1. Check if you are using Cisco Secure FCC

Record the version and management architecture that are active.

2. Install the hotfix or fixed release

Cisco has made hot fixes and fixed software versions available. There is no workaround who completely solves the vulnerability.

3. Check the accessibility of the management interface

Cisco explicitly notes that the attack area is smaller when the FCC management interface is not publicly accessible from the internet.

4. Check for compromise

Cisco publishes Indicators of Compromise and a specific log check. When clues are found, Cisco advises immediately contact with Cisco TAC.

5. Do not automatically consider patches as the end of the incident

Cisco warns that hotfixes prevent future abuse, but do not remove existing compromise automatically.

The wider lesson

Firewalls may be fully updated while the central management platform remains vulnerable.

Vulnerability management should therefore also look at firewalls, VPN gateways, management servers, routers, remote access systems and management interfaces.

Know what you're using, what's accessible from the Internet and who's responsible for quick security updates.

Read how to organize this structuralally with vulnerability management and how you control updates with patch management.

What can you check directly?

Are you using Cisco Secure Firewall Management Center?

  • Check the used version immediately.
  • Install the current Cisco hotfix/fixed release.
  • Check that the management interface is accessible to the public.
  • Run the Cisco-IoC check.
  • Initiate incident response at clues for compromise.
  • Ask your IT supplier for demonstrable confirmation when management has been outsourced.

Sources and deepening

Based on official frameworks and practical implementation

The source pages provide the formal background. Kynexis Information Security translates this information into an executable approach for your organisation, sector and risk profile.

View Cisco Security Advisory - CVE-2026-20079View Cisco Talos - Active exploitation of Cisco Secure Firewall Management Center vulnerabilitiesView NCSC - Severe Vulnerabilities in Cisco Secure Firewall Management Center