AnySec
CVE-2026-20079: root access on your Cisco Firewall Management Center
← InsightsResponse · 6 min read

CVE-2026-20079: root access on your Cisco Firewall Management Center

CVE-2026-20079 is a CVSS 10.0 unauthenticated root RCE in Cisco Secure FMC, now confirmed exploited by a nation-state group and a ransomware operator. What to check in 24 hours.

By AnySec EngineeringAnySec engineering

The short answer

CVE-2026-20079 is a CVSS 10.0 unauthenticated authentication bypass in Cisco Secure Firewall Management Center (FMC) that lets a remote attacker execute commands as root with no credentials at all. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09, and Cisco has confirmed exploitation dating back to at least 2026-07-23 — by the Russian state-sponsored group Sandworm, among others. A second, related Cisco FMC flaw (CVE-2026-20316, hardcoded static credentials) has separately been exploited by the Qilin ransomware operator for initial access since its 2026-07-29 disclosure. If FMC manages your Cisco Firepower firewall estate and its web interface is reachable from anywhere it shouldn't be, treat this as an active incident to rule out, not a routine patch cycle.

What CVE-2026-20079 actually is

The flaw comes from an improperly handled system process that gets created when an FMC host boots. Under specific conditions, a partial authenticated session tied to that boot-time process persists in the appliance's database. If an attacker can reach the web interface before anything clears that session, crafted HTTP requests can turn it into root-level command execution — no login, no user interaction, no prior foothold. Cisco has already patched its own cloud-hosted Security Cloud Control service; this specifically hits on-premises, self-managed FMC deployments.

What makes this more than a single-CVE story is that it isn't operating alone. CVE-2026-20316 — hardcoded static credentials for a low-privileged account on the same FMC web interface, disclosed 2026-07-29 — is being used by the Qilin ransomware operator for initial access, while CVE-2026-20079 has been tied to Sandworm activity. Two different classes of attacker, financially motivated and state-sponsored, converging on the same management-plane product in the same few months is a signal in itself: FMC's web interface is currently a live target, not a theoretical one.

Why a firewall manager, specifically

FMC isn't a firewall — it's the console that configures and manages a fleet of Cisco Firepower/Secure Firewall appliances, which is exactly why compromising it is disproportionately valuable to an attacker. Root access on the manager means the ability to read and rewrite the rules for every firewall it controls, not just the one host the vulnerability was found on. That's the same underlying pattern behind two other management-plane bugs covered here recently — CVE-2026-19490 on Citrix NetScaler Gateway and CVE-2026-16232 on Check Point's SmartConsole — appliances that authenticate or manage everything else in an estate routinely carry more blast-radius than almost anything they're protecting, and they're the least frequently pentested part of it because they're assumed to be "internal."

What to check in the first 24 hours

  1. Confirm whether your FMC is on-premises or cloud-delivered. Cisco's Security Cloud Control (cloud-hosted management) is already patched; if you manage Firepower through an on-prem FMC appliance, you're in scope for this check.
  2. Check your FMC software version against Cisco's own advisory and apply the hot fix for your release branch immediately. Cisco has published hot fixes across current release trains and has a broader hardening release scheduled; don't wait for it — the hot fix is what closes the immediate exposure.
  3. Restrict the FMC management interface to trusted administrative networks only. This isn't a full fix — Cisco states there is no workaround that fully addresses the flaw — but removing public-internet reachability from the web interface closes the path this vulnerability needs.
  4. Separately confirm exposure to CVE-2026-20316 (the static-credentials flaw disclosed 2026-07-29) if you haven't already — it's a different bug on the same product, being actively used by a ransomware operator for initial access, and patching one doesn't address the other.
  5. Review FMC access and configuration-change logs back to at least 2026-07-23 — the earliest date log evidence has pointed to for this vulnerability — for authentication events with no matching legitimate session, unexpected admin actions, or configuration changes to managed firewall policies you can't tie to a change ticket. Cisco has warned that its hot fixes prevent future exploitation but don't remediate a host that's already compromised, so this review matters even after patching.

What this doesn't tell you

  • Patching the FMC host doesn't confirm the managed firewalls weren't reconfigured first. If FMC was compromised before you patched, review the actual rule sets pushed to every firewall it manages, not just the manager itself.
  • This is not exploitation guidance. Nothing here describes how the boot-time session issue is actually triggered — only how to identify exposure, patch, and check for prior compromise.
  • This doesn't cover the rest of your remote-access and management-plane estate. FMC is one privileged console among potentially several (VPN concentrators, other vendors' firewall managers, jump hosts) — see the NetScaler and Check Point posts for the same pattern in different products, not a substitute for auditing your specific estate.

Next step

If Cisco FMC manages any part of your perimeter firewall estate, confirm your deployment model, apply the hot fix, and run the log review today regardless of whether you believe you were targeted — the combination of a CVSS 10.0 score, no full workaround, and confirmed exploitation by both a state-sponsored group and a ransomware operator on the same product family puts this ahead of routine patch-cycle timing. If you want the broader management-plane and remote-access exposure reviewed rather than just this one appliance, our Security Hardening engagement scopes internet-facing admin consoles, VPN concentrators, and firewall managers for exactly this class of exposure — request a baseline review.

Sources and review

CVE-2026-20079's addition to the CISA Known Exploited Vulnerabilities catalog on 2026-09-09 and the four-CVE batch it was added in are cited to CISA's own alert. CVSS score, the boot-time session mechanism, no-workaround status, and cloud-service (Security Cloud Control) patch status are cited to BleepingComputer's reporting, cross-checked against Help Net Security's reporting on the exploitation timeline, the related CVE-2026-20316 static-credentials flaw, and threat-actor attribution (Sandworm, Qilin). No exploitation technique or proof-of-concept is described or referenced beyond what's needed to identify exposure. Author: AnySec Engineering. Published 2026-09-12.


Related reading

Rather not learn this in production.

Talk to the engineers behind these write-ups — no sales script, a straight read on where you stand.

Get a fixed quote