Cisco has confirmed that a critical authentication bypass vulnerability in its Secure Firepower Management Center (FMC) is being actively exploited in the wild. The flaw, tracked as CVE-2026-20079, carries a maximum CVSS severity score of 10.0 and allows unauthenticated remote attackers to obtain root-level access to the underlying operating system.
Following the confirmation of active abuse on September 9, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies and critical infrastructure operators have been directed to remediate the flaw immediately, as the window for exploitation has narrowed significantly since Cisco’s initial disclosure of the bug earlier this year.
Exploitation via Root Access and Chaining
The vulnerability stems from an improper system process created during the device’s boot sequence. By sending crafted HTTP requests to the web-based management interface of an on-premises Secure FMC appliance, an attacker can bypass authentication entirely. Because the affected process runs with elevated privileges, successful exploitation grants the attacker full root access, providing total control over the management center and potentially the security policies of managed firewalls.

According to technical analysis from Cisco Talos, threat actors are not relying on this bypass alone. In several observed attacks, adversaries have chained CVE-2026-20079 with a second vulnerability, CVE-2026-20316. This secondary flaw involves the use of static or hardcoded credentials, which further simplifies the process of escalating privileges and maintaining persistence within the compromised network.
Attribution to Sandworm and Crimeware Groups
Cisco has linked the exploitation to at least three distinct threat clusters. One of the primary actors identified is the Russian-linked Sandworm APT (tracked by some researchers as UAT-11823). This group is known for deploying highly destructive malware and sophisticated persistence mechanisms. In these campaigns, Sandworm has been observed deploying variants of the Cyclops Blink malware, which targets network devices to create a modular botnet for further intelligence gathering or disruptive operations.
In addition to state-sponsored activity, a separate crimeware cluster tracked as UAT-12197 has been observed leveraging the flaw. The involvement of both high-tier APTs and financially motivated actors suggests that the vulnerability is being widely targeted across different sectors.
Forensic Indicators and Mitigation
Administrators who cannot immediately apply the necessary security updates should prioritize forensic log analysis to determine if their systems have already been breached. A specific indicator of compromise involves the execution of the script `package_info.pl`. According to the Cisco Security Advisory, administrators should search system logs for any execution of this script that references the temporary file path `/var/tmp/license.tmp`.

Cisco has stated that there are no manual workarounds or configuration changes that can mitigate this vulnerability. The only effective defense is to upgrade to a patched version of the Secure FMC software.
While on-premises versions of the FMC are vulnerable, Cisco confirmed that Cisco Security Cloud Control—the vendor’s cloud-hosted management platform—has already been patched. Customers utilizing the cloud-based version do not need to take further action, though they are encouraged to audit their managed devices for any unusual configuration changes that may have occurred prior to the patch being applied.
