Cisco firewall manager flaw rated 10 out of 10 is under active attack
A perfect-score bug in Cisco's Secure Firewall Management Center lets attackers take full control without a password. Evidence suggests exploitation started weeks before Cisco confirmed it.

Key points
- Cisco confirmed on Wednesday that CVE-2026-20079, a maximum-severity flaw in its Secure Firewall Management Center, is being actively exploited.
- The bug scores 10.0 out of 10 on the industry severity scale and lets a remote attacker take over the device as the root user without any login.
- Cisco says its security team learned of the attacks in August 2026, but a log entry it published points to exploitation as early as July 23.
- The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal civilian agencies to patch by September 12, 2026.
- Cisco says there is no workaround, only the software update, and installing the fix does not clean up devices that have already been broken into.
Cisco has confirmed that hackers are actively exploiting a top-severity flaw in the software administrators use to run its firewalls. The bug, CVE-2026-20079, sits in Secure Firewall Management Center, known as FMC, which is the central console for managing Cisco firewalls across a company.
It scores a perfect 10.0 on the CVSS severity scale, the industry's 0-to-10 rating for how bad a flaw is. A perfect 10 means it is as bad as it gets.
What does the bug actually let attackers do?
It lets an outsider skip the login screen entirely and run commands on the firewall manager as the root user, the account with total control. No password. No stolen session. Just a specially crafted web request sent to the device's admin interface.
This is an authentication bypass, meaning the system fails to properly check who is knocking before opening the door. Once inside as root, an attacker can read configurations, push changes to every firewall the console manages, or use the box as a foothold deeper into the network. Multi-factor authentication would not have helped here, because the flaw skips the login check altogether.
Who is affected and what needs patching?
The flaw affects Cisco Secure FMC Software and the Cisco Security Cloud Control Firewall Management service. Cisco says it has already fixed the cloud-hosted version itself, so cloud customers do not need to act. Everyone running FMC on their own hardware needs to install the latest release. There is no workaround.
| Detail | Value |
|---|---|
| CVE ID | CVE-2026-20079 |
| CVSS score | 10.0 (maximum) |
| First disclosed | March 2026 |
| Exploitation confirmed | August 2026 |
| CISA patch deadline (federal agencies) | September 12, 2026 |
| Related flaw | CVE-2026-20316 (static credentials) |
How long has this been going on?
Probably longer than Cisco first let on. Cisco's own advisory says its Product Security Incident Response Team became aware of exploitation in August 2026. But indicators of compromise, the digital fingerprints attackers leave behind, tell a slightly older story.
On July 29, Cisco disclosed a separate FMC flaw, CVE-2026-20316, caused by a built-in account with a hardcoded password. Cisco confirmed that one had been exploited. As BleepingComputer noted at the time, Cisco quietly added the same fingerprints to the CVE-2026-20079 advisory without saying it had been exploited too.
The example log line Cisco published, showing suspicious use of a licensing script in /var/tmp/license.tmp, is dated July 23. That is weeks before Cisco publicly acknowledged attacks on the perfect-10 bug. The matching fingerprints, matching hot fixes, and July log entry all point to the two flaws being used together in the same intrusions.
What should defenders do right now?
Patch, then hunt. Cisco tells administrators to search /var/log/messages for activity involving /var/tmp/license.tmp. If you find it, Cisco warns the fix will stop future attacks but will not clean up a box that is already owned. Call Cisco's Technical Assistance Center and treat the device as compromised.
CISA has given U.S. federal civilian agencies until September 12, 2026 to sort it out. Everyone else should treat that as a sensible ceiling, not a target.



