endoflife.ai
Cisco FMC Cisco FTD EOS Edge Device List Exploited & Unpatchable EOL Watch

Cisco FMC CVE-2026-20079: Fixed on Six Trains, Silent on 7.3 and 7.1

By Scott Bissett  ·  Published: September 10, 2026  ·  EOL Watch — news analysis  ·  Read at Cisco's advisory, Cisco Talos and CISA's catalog on the day of listing; lifecycle dates from Cisco's own FMC bulletins.

Cisco's Secure Firewall Management Center has a CVSS 10.0 authentication bypass that is being exploited right now, and the fix exists only if you are on one of six release trains. The advisory, cisco-sa-onprem-fmc-authbypass-5JPp45V2, was first published in March and updated on the day CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, September 9, 2026. Cisco's own summary: an unauthenticated, remote attacker can bypass authentication on the FMC web interface, execute script files and obtain root on the underlying operating system. No workarounds. Cisco's PSIRT says it became aware of active exploitation in August.

The same day, Cisco Talos described three separate intrusion clusters on FMC appliances. One drops web shells and steals credentials. One ends in a variant of Cyclops Blink, the malware the United States and United Kingdom previously attributed to the Russian state group Sandworm. One behaves like a Qilin ransomware affiliate. That is the whole spectrum of attacker in one product in one week.

The lifecycle fact that decides your week. Cisco's hot fixes cover FMC 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. FMC 7.3 is not in the advisory, in either table. Cisco's own lifecycle bulletin for 7.3 puts its End of Vulnerability/Security Support at May 18, 2026. FMC 7.1 is not there either; its security support ended on December 21, 2024. Under Cisco's stated policy, a train past that milestone no longer receives security fixes, and the advisory is consistent with the policy. An FMC on 7.3 today is running a maximum-severity, actively exploited flaw with no patch to apply.
Quick answer: Cisco Secure Firewall Management Center 10.0 is supported, with no end-of-life or end-of-support date announced yet. The next Cisco Secure Firewall Management Center version to reach end of life is 7.2, on November 18, 2026. 6 of 12 tracked Cisco Secure Firewall Management Center versions are past end of life; the most recent to reach it, 7.3, did so on May 18, 2026. Every Cisco Secure Firewall Management Center version's release and end-of-support date is on the Cisco Secure Firewall Management Center lifecycle page.

What Cisco fixed

Cisco published hot fixes rather than full releases so that customers could patch inside a maintenance window. The advisory's hot-fix table, as of its September 9 update:

FMC release trainHot fixTrain status on our data
7.0Hotfix GB 7.0.9.1-3Security support to November 18, 2026
7.2Hotfix HL 7.2.11.1-4Security support to November 18, 2026
7.4Hotfix HG 7.4.7.1-3Supported, no end date announced
7.6Hotfix CY 7.6.5.1-2Supported, no end date announced
7.7Hotfix AM 7.7.12.1-2Security support to September 29, 2027
10.0Hotfix P 10.0.1.1-2Supported, no end date announced

Cisco's cloud-delivered Security Cloud Control Firewall Management was patched by Cisco with no customer action. Firewall Device Manager, ASA software and FTD software are confirmed not vulnerable. Talos adds that a comprehensive hardening release, bundling these hot fixes with other internally found fixes, follows the week of September 14.

Running Cisco Secure Firewall Management Center past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers Cisco Secure Firewall Management Center is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

What Cisco did not fix, and why the calendar explains it

Three trains are missing from the advisory that are still running in real networks. None of the three is called out as unfixable; they simply do not appear. Their lifecycle dates, from Cisco's per-train bulletins as we serve them on the FMC product page, explain the silence:

TrainEnd of SW Maintenance ReleasesEnd of Vulnerability/Security SupportLast Date of SupportIn the advisory?
7.3May 18, 2026May 18, 2026November 30, 2027No
7.1December 21, 2024December 21, 2024December 31, 2025No
6.7July 9, 2022July 9, 2022July 31, 2024No

Read the middle column. Cisco's lifecycle language is precise: after the End of Vulnerability/Security Support date, Cisco Engineering may no longer release fixes for security issues. The Last Date of Support that follows is technical assistance, not patches. FMC 7.3 has a further year of the former and none of the latter. That is why a maximum-severity flaw exploited by a state group can have a fix for 7.2, which ends security support in November, and nothing for 7.3, which ended it in May. The version number is newer; the support clock is older.

What we are not saying. Cisco has not declared 7.3 unfixable; it has omitted it, consistent with its lifecycle. The hardening release Talos announced for the week of September 14 is the moment that becomes certain either way. This article is written on the day of listing and states the advisory as it stood then; the lifecycle dates in it are bound to our data and refresh at every build. We are holding our own Exploited & Unpatchable entry until Cisco's hardening release settles the question.

Who is on the other end

Talos's write-up is unusually specific for the first day. Cluster one, UAT-12197, exploits CVE-2026-20079 to place a JSP web shell in the FMC's Tomcat web root, load a Java command executor and exfiltrate credentials. Cluster two, UAT-11823, chains CVE-2026-20079 with a second flaw, CVE-2026-20316, to a reverse shell and proxy tooling, ending in a variant of Cyclops Blink. Cluster three, UAT-11988, entered through static credentials (CVE-2026-20316) and lived off the land inside FMC's own tooling to map the victim's environment, with tactics Talos matched to Qilin affiliates. Talos assesses it with high confidence as a ransomware operator.

The FMC's job makes this worse than a single appliance. It holds the policy, the credentials and the topology for every firewall it manages. A root shell on the manager is a map of the estate.

What to do, by train

7.0, 7.2, 7.4, 7.6, 7.7 or 10.0: apply the hot fix from the Software Center now, ahead of CISA's federal deadline three days after listing. Then read Cisco's indicators of compromise before you trust the box: Cisco says the hot fixes prevent future exploitation and may not address an existing compromise, and the advisory points compromised customers to TAC for recovery.

7.3: there is nothing to apply. Restrict the management interface to trusted administrative networks today, hunt for the Talos indicators, and treat the upgrade to a supported train as this week's work, not this quarter's. 7.4 and 7.6 carry no announced end date; 7.7 runs to September 29, 2027. Check the FMC page for the train-by-train dates and the FTD page for the devices under it, because FMC and FTD trains move together.

7.1 or any 6.x: the same, with less room. These trains are past every fix milestone; 7.1 is past even its Last Date of Support. An appliance on them is unsupported in Cisco's own words, and exploited in Talos's.

Everyone: put a reminder on the week of September 14. If Cisco's hardening release covers 7.3, this page will say so; if it does not, the omission has become the answer.

Frequently Asked Questions

Which Cisco FMC versions have a fix for CVE-2026-20079?

Cisco's advisory lists hot fixes for six Secure FMC release trains: 7.0 (hot fix 7.0.9.1-3), 7.2 (7.2.11.1-4), 7.4 (7.4.7.1-3), 7.6 (7.6.5.1-2), 7.7 (7.7.12.1-2) and 10.0 (10.0.1.1-2). Cisco's cloud-delivered Security Cloud Control Firewall Management was fixed by Cisco with no customer action.

Is there a fix for FMC 7.3 or 7.1?

Not in the advisory as updated on the day CISA listed the flaw. Cisco's own lifecycle bulletin puts FMC 7.3's End of Vulnerability/Security Support on May 18, 2026 and 7.1's on December 21, 2024, and neither train appears in the hot-fix table. Talos says a hardening release follows the week of September 14; until Cisco states otherwise, treat 7.3, 7.1 and every 6.x train as having no fix and plan the upgrade.

Who is exploiting CVE-2026-20079?

Cisco Talos described three clusters on September 9, 2026: UAT-12197 (web shells, a Java-based command executor and credential theft), UAT-11823 (a variant of Cyclops Blink, malware previously attributed by the United States and United Kingdom to Sandworm) and UAT-11988, whose tactics Talos matched to Qilin ransomware affiliates; the third cluster entered through the companion flaw CVE-2026-20316. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on September 9, 2026.

Is there a workaround?

No. Cisco's advisory states there are no workarounds. Restricting management-interface access to trusted administrative networks reduces exposure but does not replace the hot fix, and the hot fixes prevent future exploitation only: Cisco says they may not address an existing compromise.

Related

© 2026 endoflife.ai · How we verify our dates · API · About