Skip to content

CVE-2026-20079: Cisco Secure FMC Authentication Bypass to Root RCE

HERMES

HERMES THREAT SCORE & ENTERPRISE RISK

Target: Cisco Secure Firewall Management Center (FMC) - Web Management Plane
Confidence: 99%
98 / 100
CRITICAL

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 20 / 20
Threat Activity 20 / 20
Weaponization 20 / 20
Exposure 19 / 20
Prevalence 19 / 20
Impact 20 / 20
Exploit Maturity 20 / 20
Attack Chain Potential 20 / 20
βš–οΈ Divergence & Operational Rationale

Hermes rates CVE-2026-20079 at 98 (CRITICAL). As the centralized control plane managing enterprise perimeter firewalls (FTD and ASA), unauthenticated root compromise of Cisco FMC leads to the catastrophic collapse of all network segmentation, credential exposure, and immediate weaponized pivoting into internal crown-jewel segments.

πŸ•ΈοΈ Connected Knowledge Graph & Provenance

CVE-2026-20079: Cisco Secure FMC Authentication Bypass to Root RCEVULNERABILITY

Connected Nodes: 1
Active Relationships (Outgoing)
→ affectsPRODUCTCisco Secure Firewall Management Center
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

πŸ” Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in Cisco Secure Firewall Management Center documented in Hermes dossier.”

Supporting Verified Evidence:

ParameterTechnical SpecificationOperational Impact
CVE IdentifierCVE-2026-20079Universal vulnerability identifier
Vendor Advisorycisco-sa-onprem-fmc-authbypass-5JPp45V2Cisco Security Advisory publication
Cisco Bug IDsCSCwr96008, CSCwt95974Cisco PSIRT engineering defect tracking
CVSS v3.1 Score10.0 (Critical)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
FIRST EPSS Score35.95% (98.37th percentile)Upper-tier exploitation probability
CISA KEV StatusAdded on September 9, 2026Mandatory deadline: September 12, 2026 (BOD 26-04)
Vulnerable ComponentHTTPS web management interface (boot-time process)Port TCP 443 / 8443
Required PrivilegesNone (Unauthenticated)Remote network exploitation vector
Gained Privilegesroot (Underlying Linux OS Superuser)Total device and management takeover

CVE-2026-20079 impacts all major active release trains of on-premises Cisco Secure FMC:

  • Cisco Secure FMC 7.0: Affected (Fixed in Hotfix GB-7.0.9.1-3 / version 7.0.9 or later);
  • Cisco Secure FMC 7.2: Affected (Fixed in Hotfix HL-7.2.11.1-4 / version 7.2.11 or later);
  • Cisco Secure FMC 7.4: Affected (Fixed in Hotfix HG-7.4.7.1-3 / version 7.4.7 or later);
  • Cisco Secure FMC 7.6: Affected (Fixed in Hotfix CY-7.6.5.1-2 / version 7.6.5 or later);
  • Cisco Secure FMC 7.7: Affected (Fixed in Hotfix AM-7.7.12.1-2 / version 7.7.12 or later);
  • Cisco Secure FMC 10.0: Affected (Fixed in Hotfix P-10.0.1.1-2 / version 10.0.1 or later).

The root cause of CVE-2026-20079 is categorized under CWE-288 (Authentication Bypass Using an Alternate Path or Channel) combined with unrestricted sudo privilege execution.

CVE-2026-20079 Execution Flow on Cisco Secure FMC:
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 1. Remote Unauthenticated Attacker β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Crafted HTTP requests (TCP 443)
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 2. Improper Boot-Time System Process β”‚
β”‚ β€’ Internal dispatch handler registered during init β”‚
β”‚ β€’ Fails to enforce web session authentication filters β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ File write / authentication bypass
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 3. Temporary File Dropped on Target β”‚
β”‚ β€’ /var/tmp/license.tmp (under 'www' webserver context) β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Passwordless sudo invocation
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 4. Privileged Perl Utility Invocation β”‚
β”‚ β€’ sudo /usr/local/sf/bin/package_info.pl /var/tmp/... β”‚
β”‚ β€’ Unsanitized argument parsing & command dispatch β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Elevation to operating system
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 5. Arbitrary Code & Script Execution as ROOT β”‚
β”‚ β€’ Backdoors, reverse shells, web shell deployment β”‚
β”‚ β€’ Extraction of configuration database & crypto keys β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

During appliance initialization, Cisco FMC launches background system daemons responsible for internal package management, licensing validation, and inter-service dispatching. One of these processes establishes local listener hooks directly mapped into the webserver (Apache/Nginx) request routing table.

However, requests directed toward these endpoints do not traverse the standard authentication validation stack (which inspects administrative session tokens and RBAC credentials). An unauthenticated remote attacker with network reachability to port 443/8443 can target these unprotected URIs to deliver arbitrary instructions.

Once the alternate channel is reached, the backend process accepts package and license update commands. The unprivileged web server account (www) possesses sudoers permissions to invoke the administrative Perl utility:

Terminal window
sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm

By providing a crafted /var/tmp/license.tmp file or exploiting parameter injection in package_info.pl, the attacker triggers command evaluation directly within the Perl script context. Because the script executes via sudo as root, the attacker immediately attains unrestricted root shell access on the underlying Linux OS.


CVE-2026-20079 is actively exploited in the wild by sophisticated threat actors targeting edge infrastructure devices.

In enterprise network architectures, Cisco FMC orchestrates all perimeter Secure Firewall Threat Defense (FTD) sensors. Gaining root access to FMC grants attackers catastrophic capabilities:

  1. Infrastructure Secret Harvesting: Extraction of IPsec VPN pre-shared keys (PSKs), administrative passwords, and private cryptographic certificates stored within FMC;
  2. Defensive Telemetry Blindspots: Silently altering Snort inspection rules, whitelisting adversary IP ranges, or disabling logging to mask lateral movement;
  3. Internal Network Pivoting: Utilizing the compromised FMC appliance as an internal pivot host into isolated Out-Of-Band (OOB) management and data center networks.

Telemetry from Cisco Talos indicates threat actors chain CVE-2026-20079 with secondary local vulnerabilities (such as CVE-2026-20316) to establish persistent backdoors, install obfuscated web shells within FMC web directories, and configure hidden cron jobs that survive system reboot cycles.

This attack pattern mirrors large-scale edge gateway exploitation campaigns observed with Ivanti EPMM CVE-2026-1281 and critical infrastructure attacks targeting backup platforms such as Veeam Backup & Replication CVE-2026-21669.


In accordance with CISA’s Forensics Triage Requirements under BOD 26-04, incident response teams must audit Cisco FMC appliances for evidence of historical compromise.

Access the Cisco Secure FMC appliance via SSH, enter expert mode, and inspect system logs:

Terminal window
expert
admin@firepower:~$ sudo su
root@firepower:/home/admin# zgrep "package_info.*license" /var/log/messages*

If log records contain output matching:

Jul 23 16:16:33 firepower sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm

the appliance presents a definitive indicator of compromise. The attacker has leveraged CVE-2026-20079 to invoke the privileged Perl utility with the temporary license file.

Filesystem Artifacts

  • Presence of /var/tmp/license.tmp or anomalous files in /var/tmp/ and /tmp/.
  • Unrecognized PHP, Perl, or shell scripts deposited in /usr/local/sf/htdocs/ or /var/www/.
  • Unauthorized SSH keys appended to /root/.ssh/authorized_keys or /home/admin/.ssh/authorized_keys.

Network & Process Anomalies

  • Outbound TCP connections initiated from the FMC management IP to unknown external IP addresses (C2 beaconing).
  • Unexpected child processes spawned by Perl or web server processes (/bin/sh, /bin/bash, nc, python).

To detect and prevent network exploitation attempts targeting CVE-2026-20079, Cisco Talos published the following Snort signatures:

# Snort 2 Talos Signatures:
66572, 66573, 66574, 66575, 66576, 66577, 66581, 66589, 66590, 66594, 66595, 66601, 66602, 66603, 66604
# Snort 3 Talos Signatures:
301523, 301524, 301525, 301527, 301528, 301529, 301531, 301532

These rules monitor inbound HTTP/HTTPS traffic targeting unauthenticated endpoints and drop requests containing malformed license and package payload parameters.


  1. Perimeter Isolation:
    Ensure the Cisco FMC management interface is completely inaccessible from the public internet. Restrict all administrative access to dedicated Out-Of-Band (OOB) management VLANs via strict Access Control Lists (ACLs) or bastion hosts.

  2. Forensic Pre-Upgrade Verification:
    Execute zgrep "package_info.*license" /var/log/messages* in expert mode. If compromise indicators are detected, applying the hotfix will not evict established attackers. Initiate an emergency incident response procedure and engage Cisco TAC immediately.

  3. Deploy Official Cumulative Hotfixes:
    Download and install the appropriate hotfix package from the Cisco Software Center:

    • 7.0 Release Train: Install Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar;
    • 7.2 Release Train: Install Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar;
    • 7.4 Release Train: Install Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar;
    • 7.6 Release Train: Install Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar;
    • 7.7 Release Train: Install Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar;
    • 10.0 Release Train: Install Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar.
  4. Post-Remediation Secret Rotation:
    If suspicious activity is discovered or suspected prior to patching, perform a complete rotation of:

    • Local and domain administrative account passwords used on FMC;
    • API credentials, integration tokens, and service accounts;
    • IPsec VPN pre-shared keys (PSKs) deployed to managed firewalls;
    • Digital certificates and private keys stored within FMC certificate stores.