CISA added CVE-2026-20079 to the Known Exploited Vulnerabilities catalog on September 9, 2026 with a three-day remediation deadline, the same day Cisco revised a six-month-old advisory to say attackers had been exploiting the flaw since August.
What happened
Cisco first published advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 on March 4, 2026. It describes an authentication bypass in the web interface of Cisco Secure Firewall Management Center. On September 9, 2026, Cisco issued version 2.5 of that advisory. The revision history records a single changed section, “Exploitation and Public Announcements,” and a one-line description of the change: “Updated to indicate that active exploitation has been observed.”
The advisory now states: “In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.”
CISA added the CVE to the KEV catalog the same day. Catalog version 2026.09.09, released at 7:00 p.m. UTC on September 9, 2026, carries a dateAdded of 2026-09-09 and a dueDate of 2026-09-12 — three days. The entry’s forensicTriage field is set to Yes, which under BOD 26-04 obliges federal civilian agencies not only to remediate within the window but to carry out a forensic triage of the asset to assess whether it has been compromised. knownRansomwareCampaignUse is Unknown.
Cisco scores the flaw 10.0 on CVSS v3.1, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, with a security impact rating of Critical. The weakness is CWE-288, authentication bypass using an alternate path or channel. Cisco attributes the flaw to an improper system process initialized at boot time, and says an unauthenticated, remote attacker can send crafted HTTP requests to “bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.”
Affected releases are Cisco Secure Firewall Management Center Software 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Cisco says Security Cloud Control Firewall Management, the hosted equivalent, has already been patched on Cisco’s side. Remediation for on-premises deployments is a hot fix rather than a maintenance release, one per train: Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar for 7.0, Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar for 7.2, Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar for 7.4, Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar for 7.6, Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar for 7.7, and Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar for 10.0. On workarounds the advisory is explicit: “There are no workarounds that address this vulnerability.”
The revision history is worth reading in full. Version 1.0 was the initial public release on March 4. Version 2.0, on July 31, added Cisco Bug ID CSCwt95974, indicators of compromise, and the hot fixes. Versions 2.1 and 2.2 landed the same day, refining a code example and, in Cisco’s words, making it “clear to contact TAC if compromise is suspected.” Versions 2.3 and 2.4 followed on August 5, updating a CLI command and the customer-action text around the hot fixes. Then nothing until version 2.5 on September 9.
In between, a working exploit went public. On August 20, 2026, a post to the Full Disclosure mailing list from an author using the name Banks Tools published an independently reproduced proof-of-concept against Secure Firewall Management Center 10.0.1-1, describing it as an authentication-bypass-to-root-RCE chain and shipping Python modules for fingerprinting, bypass validation, root verification, exploitation, and cleanup. The post says it reproduces an exploit that had already been documented elsewhere. NVD carries that mailing-list post as a reference on the CVE record.
Why it matters
The interval that matters here is not March to September. It is August to September 9. Cisco’s own sentence places its awareness of exploitation in August 2026 and its publication of that fact on September 9 — a gap of somewhere between nine and forty days, depending on where in August the PSIRT learned of it. The advisory does not narrow it, and a reader cannot narrow it either. What can be said is that for at least part of that window, defenders reading the most recent version of Cisco’s advisory would have seen a critical bug with hot fixes available and no indication that anyone was using it.
That reading understates a signal Cisco had already sent. On July 31 — four months after initial disclosure, and before any statement about exploitation — Cisco added indicators of compromise to the advisory, then amended it twice more the same day to make sure customers knew to contact TAC if they suspected compromise. Vendors do not usually write compromise-detection guidance and a call-TAC instruction for a bug nobody is touching. The artifacts to hunt with were published on July 31; the reason to prioritize the hunt was published on September 9. An organization that patches by severity would have had the hot fix by early August. An organization that patches by observed exploitation would still be waiting on Tuesday.
The asset is the second reason this one is worth moving on. Secure Firewall Management Center is not a firewall — it is the console that configures them, pushes policy to them, and holds the credentials and objects that describe an organization’s whole enforcement posture. Root on the manager is not equivalent to root on one appliance. It is administrative reach over every device the manager owns, plus whatever else the box can see from its position inside the management network. The S:C element of Cisco’s vector, scope changed, is doing real work in that 10.0 rather than inflating it.
The score is Cisco’s own, and it is the only one on the record. NVD still lists CVE-2026-20079 as “Awaiting Analysis,” last modified August 26, 2026, with a single secondary CVSS entry sourced to [email protected] and no NIST primary score. As of this writing, NVD has also not attached CISA’s KEV fields to the record: there is no cisaExploitAdd and no cisaActionDue there. The deadline in this story is read from CISA’s own catalog data file, not from NVD, and the two will agree in a day or so.
One pattern is visible in that catalog file and is worth stating plainly, because it is measurable rather than transcribed. BOD 26-04 defines four remediation bands — three days, 14 days, 60 days, and a deferral tier that waits for the next scheduled upgrade. Of the 86 catalog entries added since the directive took effect on June 10, 2026, 65 carry a three-day deadline and 21 carry 14 days. Not one has carried 60 days, and not one has been deferred. The short clock is not the exception under this directive; in practice it is the only other option besides two weeks. Which combination of internet exposure, KEV listing, exploit automation, and technical impact produces which band is a question this publication cannot answer from the primary source, because CISA publishes that mapping only as images in Appendix A and the public transcriptions of it disagree with one another. The counts above need no table.
What to do
Identify every on-premises Secure Firewall Management Center, including standalone virtual appliances and any instance parked in a management VLAN that nobody has looked at since it was built. Cisco lists 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 as affected. Apply the hot fix matching the train, by the file names above, from the Cisco Software Center. There is no configuration change that closes this, so do not spend time looking for one; restricting network reachability to the web interface reduces exposure but is not a fix and Cisco does not offer it as one.
Federal civilian agencies have until Saturday, September 12, 2026. The forensicTriage flag means patching alone does not discharge the obligation — the asset also has to be triaged for evidence of compromise. Everyone else should treat the same date as a sensible target, and should run the triage regardless of sector: given a public proof-of-concept dated August 20 and vendor-confirmed exploitation beginning sometime in August, an unpatched manager exposed to the network has been reachable by a known-good exploit for weeks. Cisco’s advisory carries the indicators of compromise and the CLI command added in the July 31 and August 5 revisions; use that section, and contact Cisco TAC if the check comes back positive rather than reimaging over the evidence.
Sourcing note
Checked: Cisco’s advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 at sec.cloudapps.cisco.com, including its revision history, exploitation statement, hot fix list, and workaround statement; the NVD record for CVE-2026-20079; the Full Disclosure post of August 20, 2026 carried as a reference on that record; and CISA’s KEV catalog data.
cisa.gov returns 403 to automated fetching, so the KEV entry was read from cisagov/kev-data on GitHub, which CISA maintains as a mirror of the cisa.gov/kev data files. The file used is catalog version 2026.09.09, dateReleased 2026-09-09T19:00:50.2591Z. The band counts cited above were computed from that same file.
Unresolved: Cisco does not say when in August its PSIRT learned of exploitation, how the exploitation was detected, how many customers are affected, or whether the activity is related to the August 20 public proof-of-concept. Cisco names no threat actor and this publication does not attribute the activity. NVD had not attached CISA’s KEV fields to CVE-2026-20079 at the time of writing and still shows the record as “Awaiting Analysis” with no NIST primary score; the 10.0 is Cisco’s own figure.