Knox CVE Database
/
CVE-2026-20079
Critical
10.0

CVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

Added to the CISA KEV catalog:
September 9, 2026

Overview

Cisco Secure Firewall Management Center (FMC) contains an authentication bypass flaw in its web interface that allows an unauthenticated remote attacker to execute scripts as root on the underlying operating system. The flaw stems from an improper process created at boot time that exposes an alternate path bypassing normal authentication controls. Affected versions span the 7.0 and 7.2 release lines of on-premises FMC deployments. Cisco Talos has confirmed active exploitation by multiple threat actor clusters, including a group with Sandworm tooling overlap and a ransomware operator assessed with high confidence to be a Qilin affiliate.

Vulnerability details

Affected vendor
Cisco
Affected product
Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Weakness type (CWE)
CWE-288

The vulnerability is classified as CWE-288, authentication bypass using an alternate path or channel. At boot time, the FMC web interface creates an improper system process that leaves an alternate HTTP-accessible path reachable without passing through the product's authentication controls. Any crafted HTTP request directed at this path causes the device to execute script files under root privileges, without requiring credentials or any prior foothold. The flaw is architectural rather than configuration-dependent: Cisco states it affects devices regardless of configuration.


An attacker with network access to the FMC management interface sends crafted HTTP requests to the alternate path, obtaining root-level (uid=0) code execution immediately. A public proof-of-concept implementing fingerprinting, bypass verification, and exploitation steps has been published. In observed intrusions, attackers followed initial access with web shell deployment in the Tomcat webroot, placement of a JAR-based command executor to query internal databases for credentials, and establishment of Netcat-based reverse shells via a malicious license.tmp file executed by the package_info.pl utility. The advisory notes that restricting the management interface from public internet access reduces the attack surface, but network reachability is the only precondition.

Severity and impact

10.0
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Run the Cisco-specified triage command in expert mode: 'zgrep "package_info.license" /var/log/messages'. Any output referencing /var/tmp/license.tmp indicates the boot-time process was abused and exploitation is likely.
  • Audit the Tomcat webroot directory for unexpected JSP or JAR files, particularly files named cmd.jar or JSP files accepting Base64-encoded class-name parameters. These are direct indicators from confirmed intrusion clusters.
  • Review FMC web server access logs for unauthenticated HTTP requests to paths outside normal administrative workflows, especially requests that succeed without a corresponding authenticated session in the audit trail.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 12, 2026

Additional hardening

  • Apply the Cisco-released hot fixes for the affected release line: for 7.0, apply Hotfix_GB-7.0.9.1-3; for 7.2, apply Hotfix_HL-7.2.11.1-4. See the vendor advisory in References for hot fix names covering additional release lines.
  • Restrict the FMC management interface to internal or out-of-band management networks only. Cisco explicitly states that removing public internet access reduces the attack surface for this vulnerability.
  • If exploitation indicators are found (license.tmp reference in logs, unexpected files in the Tomcat webroot), treat the device as compromised and contact Cisco TAC before applying hot fixes, as Cisco states hot fixes prevent future exploitation but may not address an existing compromise.
  • Audit all accounts with access to managed firewall infrastructure for credential exposure, given confirmed post-exploitation activity includes querying the FMC internal user database for authentication data.

Key dates

Published (NVD)
March 4, 2026
Added to CISA KEV
September 9, 2026
Remediation deadline
September 12, 2026
Last updated
September 10, 2026

References

Frequently asked questions

Does CVE-2026-20079 affect my FedRAMP authorization?

If Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management runs inside your authorization boundary, yes. CVE-2026-20079 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of September 12, 2026, a date that has already passed. For a FedRAMP-authorized service, an unpatched KEV is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency. Remediate now or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-20079?

Knox does not patch your software. Remediating Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. Applying the patch is yours to own; managing compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-20079 surfaces, exposure appears during ongoing monitoring rather than waiting until an assessor flags it at scheduled review time. That gap matters: earlier visibility means earlier remediation.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-20079's remediation deadline of September 12, 2026 has passed. What happens now?

If CVE-2026-20079 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult agency conversation. Closing the finding out and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on stable footing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.