Skip to finding
§
High
Edge — Cisco FMC
Confirmed
CVE-2026-20079

Cisco's exploited FMC bypass gives an unauthenticated caller root command execution.

HTTP reachability to the management interface is enough to reach the vulnerable path.

Affects

Cisco Secure Firewall Management Center, the on-premises management appliance for Cisco firewalls, and the affected Cisco Security Cloud Control firewall-management service.

What it enables

Unauthenticated command execution as root on firewall-management infrastructure

Send crafted HTTP requests to the FMC web interface without credentials.→↓Bypass the normal management-interface authentication boundary through the boot-created process.→↓Invoke scripts or commands with root access to the appliance operating system.→↓Use the management-plane foothold to harvest credentials, deploy tunnels or web shells, and reach managed networks.
Why this matters

Although ranked below the Bluetooth disclosure, it leads because exploitation is active, reaches root on the firewall-management plane, and has already produced several post-compromise toolsets; the Bluetooth elevation paths remain unreproduced.

Detail and 4 sources
Required access

HTTP reachability to an affected Secure FMC management interface

Affected versions

6.4.0.13 through 6.4.0.18, 7.0.0 through 7.0.8.1, 7.1.0 through 7.1.0.3, 7.2.0 through 7.2.10.2, 7.3.0 through 7.3.1.2, 7.4.0 through 7.4.5, 7.6.0 through 7.6.4, 7.7.0, 7.7.10, 7.7.10.1, and 7.7.11, 10.0.0, FMC 7.0 without hotfix GB-7.0.9.1-3, FMC 7.2 without hotfix HL-7.2.11.1-4, FMC 7.4 without hotfix HG-7.4.7.1-3, FMC 7.6 without hotfix CY-7.6.5.1-2, FMC 7.7 without hotfix AM-7.7.12.1-2, FMC 10.0 without hotfix P-10.0.1.1-2, Secure FMC 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 installations lacking the applicable hot fix

A boot-created system process exposes an alternate route from crafted unauthenticated web requests to root-capable script execution.

Cisco observed web shells, Cyclops Blink, credential harvesting, tunnels, and ransomware staging across three intrusion clusters.

Cisco has published fixes, and CISA added the flaw to its exploited-vulnerability catalog on September 9.

Evidence
Cisco's advisory confirms unauthenticated HTTP-to-root execution and active exploitationCisco Talos documents three intrusion clusters, including web shells, Cyclops Blink deployment, credential harvesting, tunneling, and ransomware stagingCISA added CVE-2026-20079 to KEV on 2026-09-09
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 10, 2026