Cisco FMC CVE-2026-20079: Fixed on Six Trains, Silent on 7.3 and 7.1
Cisco's Secure Firewall Management Center has a CVSS 10.0 authentication bypass that is being exploited right now, and the fix exists only if you are on one of six release trains. The advisory, cisco-sa-onprem-fmc-authbypass-5JPp45V2, was first published in March and updated on the day CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, September 9, 2026. Cisco's own summary: an unauthenticated, remote attacker can bypass authentication on the FMC web interface, execute script files and obtain root on the underlying operating system. No workarounds. Cisco's PSIRT says it became aware of active exploitation in August.
The same day, Cisco Talos described three separate intrusion clusters on FMC appliances. One drops web shells and steals credentials. One ends in a variant of Cyclops Blink, the malware the United States and United Kingdom previously attributed to the Russian state group Sandworm. One behaves like a Qilin ransomware affiliate. That is the whole spectrum of attacker in one product in one week.
What Cisco fixed
Cisco published hot fixes rather than full releases so that customers could patch inside a maintenance window. The advisory's hot-fix table, as of its September 9 update:
| FMC release train | Hot fix | Train status on our data |
|---|---|---|
| 7.0 | Hotfix GB 7.0.9.1-3 | Security support to November 18, 2026 |
| 7.2 | Hotfix HL 7.2.11.1-4 | Security support to November 18, 2026 |
| 7.4 | Hotfix HG 7.4.7.1-3 | Supported, no end date announced |
| 7.6 | Hotfix CY 7.6.5.1-2 | Supported, no end date announced |
| 7.7 | Hotfix AM 7.7.12.1-2 | Security support to September 29, 2027 |
| 10.0 | Hotfix P 10.0.1.1-2 | Supported, no end date announced |
Cisco's cloud-delivered Security Cloud Control Firewall Management was patched by Cisco with no customer action. Firewall Device Manager, ASA software and FTD software are confirmed not vulnerable. Talos adds that a comprehensive hardening release, bundling these hot fixes with other internally found fixes, follows the week of September 14.
What Cisco did not fix, and why the calendar explains it
Three trains are missing from the advisory that are still running in real networks. None of the three is called out as unfixable; they simply do not appear. Their lifecycle dates, from Cisco's per-train bulletins as we serve them on the FMC product page, explain the silence:
| Train | End of SW Maintenance Releases | End of Vulnerability/Security Support | Last Date of Support | In the advisory? |
|---|---|---|---|---|
| 7.3 | May 18, 2026 | May 18, 2026 | November 30, 2027 | No |
| 7.1 | December 21, 2024 | December 21, 2024 | December 31, 2025 | No |
| 6.7 | July 9, 2022 | July 9, 2022 | July 31, 2024 | No |
Read the middle column. Cisco's lifecycle language is precise: after the End of Vulnerability/Security Support date, Cisco Engineering may no longer release fixes for security issues. The Last Date of Support that follows is technical assistance, not patches. FMC 7.3 has a further year of the former and none of the latter. That is why a maximum-severity flaw exploited by a state group can have a fix for 7.2, which ends security support in November, and nothing for 7.3, which ended it in May. The version number is newer; the support clock is older.
Who is on the other end
Talos's write-up is unusually specific for the first day. Cluster one, UAT-12197, exploits CVE-2026-20079 to place a JSP web shell in the FMC's Tomcat web root, load a Java command executor and exfiltrate credentials. Cluster two, UAT-11823, chains CVE-2026-20079 with a second flaw, CVE-2026-20316, to a reverse shell and proxy tooling, ending in a variant of Cyclops Blink. Cluster three, UAT-11988, entered through static credentials (CVE-2026-20316) and lived off the land inside FMC's own tooling to map the victim's environment, with tactics Talos matched to Qilin affiliates. Talos assesses it with high confidence as a ransomware operator.
The FMC's job makes this worse than a single appliance. It holds the policy, the credentials and the topology for every firewall it manages. A root shell on the manager is a map of the estate.
What to do, by train
7.0, 7.2, 7.4, 7.6, 7.7 or 10.0: apply the hot fix from the Software Center now, ahead of CISA's federal deadline three days after listing. Then read Cisco's indicators of compromise before you trust the box: Cisco says the hot fixes prevent future exploitation and may not address an existing compromise, and the advisory points compromised customers to TAC for recovery.
7.3: there is nothing to apply. Restrict the management interface to trusted administrative networks today, hunt for the Talos indicators, and treat the upgrade to a supported train as this week's work, not this quarter's. 7.4 and 7.6 carry no announced end date; 7.7 runs to September 29, 2027. Check the FMC page for the train-by-train dates and the FTD page for the devices under it, because FMC and FTD trains move together.
7.1 or any 6.x: the same, with less room. These trains are past every fix milestone; 7.1 is past even its Last Date of Support. An appliance on them is unsupported in Cisco's own words, and exploited in Talos's.
Everyone: put a reminder on the week of September 14. If Cisco's hardening release covers 7.3, this page will say so; if it does not, the omission has become the answer.
Frequently Asked Questions
Which Cisco FMC versions have a fix for CVE-2026-20079?
Cisco's advisory lists hot fixes for six Secure FMC release trains: 7.0 (hot fix 7.0.9.1-3), 7.2 (7.2.11.1-4), 7.4 (7.4.7.1-3), 7.6 (7.6.5.1-2), 7.7 (7.7.12.1-2) and 10.0 (10.0.1.1-2). Cisco's cloud-delivered Security Cloud Control Firewall Management was fixed by Cisco with no customer action.
Is there a fix for FMC 7.3 or 7.1?
Not in the advisory as updated on the day CISA listed the flaw. Cisco's own lifecycle bulletin puts FMC 7.3's End of Vulnerability/Security Support on May 18, 2026 and 7.1's on December 21, 2024, and neither train appears in the hot-fix table. Talos says a hardening release follows the week of September 14; until Cisco states otherwise, treat 7.3, 7.1 and every 6.x train as having no fix and plan the upgrade.
Who is exploiting CVE-2026-20079?
Cisco Talos described three clusters on September 9, 2026: UAT-12197 (web shells, a Java-based command executor and credential theft), UAT-11823 (a variant of Cyclops Blink, malware previously attributed by the United States and United Kingdom to Sandworm) and UAT-11988, whose tactics Talos matched to Qilin ransomware affiliates; the third cluster entered through the companion flaw CVE-2026-20316. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on September 9, 2026.
Is there a workaround?
No. Cisco's advisory states there are no workarounds. Restricting management-interface access to trusted administrative networks reduces exposure but does not replace the hot fix, and the hot fixes prevent future exploitation only: Cisco says they may not address an existing compromise.
Related
- Cisco Secure Firewall Management Center — every train with its End of SW Maintenance, End of Vulnerability/Security Support and Last Date of Support, from Cisco's bulletins
- Cisco Secure Firewall Threat Defense — the device trains FMC manages, which share its bulletins
- EOS Edge Device List — every edge platform we track with a CISA KEV history
- Exploited & Unpatchable — the feed of KEV entries on products past their fix window
- How we verify our dates — the rules every number on this site is held to