bleeping-computer · Crawled Sep 10, 2026

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

1 IoCs
Read original article ↗

AI Summary

Cisco has confirmed active exploitation of a critical authentication bypass vulnerability, CVE-2026-20079, in its Secure Firewall Management Center (FMC) software. The flaw, rated CVSS 10.0, allows unauthenticated remote attackers to execute commands as root by sending crafted HTTP requests. Indicators of compromise, including a specific log entry referencing '/var/tmp/license.tmp', were observed as early as July 23, 2026, suggesting exploitation began before Cisco's public awareness in August. The U.S. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by September 12, 2026.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Filename /var/tmp/license.tmp Details →