CVE-2026-20079 actively exploited is now the controlling security state for Cisco Secure Firewall Management Center operators. Cisco updated its advisory on September 9, 2026 to say its Product Security Incident Response Team had become aware of active exploitation, while Cisco Talos separately described intrusion activity involving the vulnerability. The practical change is important: an affected administrator should no longer treat this only as a routine patching task. The job is now to identify the deployed FMC release, apply Cisco’s appropriate remediation, check for signs of prior exploitation and escalate suspected compromise.
What changed with CVE-2026-20079
Cisco rates CVE-2026-20079 at CVSS 10.0. The vulnerability can allow an unauthenticated remote attacker to bypass authentication and execute scripts or commands with root privileges on an affected Secure FMC system. Cisco says there is no workaround that addresses the vulnerability.
The September 9 update materially changes the risk assessment because exploitation is no longer theoretical. Cisco Talos says it is tracking real intrusion activity and has observed attackers using the flaw as part of broader compromise operations.
What Cisco Secure FMC operators should do now
Confirm the exact Secure Firewall Management Center branch and installed release before selecting a remediation package. Do not assume a hotfix for one branch applies to another.
Cisco currently documents branch-specific hotfixes for affected 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 release trains. Follow the current Cisco advisory rather than relying on copied filenames if the advisory is revised.
Because active exploitation is confirmed, remediation should be followed by Cisco’s documented indicator-of-compromise check. Cisco describes a log search for activity associated with /var/tmp/license.tmp. The exact command and interpretation should be taken from the current advisory.
If the documented indicator appears, or other evidence suggests the FMC was compromised, do not treat installation of the hotfix as proof that the system is clean. Cisco directs customers with suspected compromise to contact Cisco TAC for recovery guidance.
Which Cisco FMC branches have hotfixes
Cisco’s September advisory lists branch-specific hotfix packages for Secure FMC 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. Administrators should use the exact current mapping in Cisco’s advisory because fixed-release guidance can change as additional software updates are released.
The key operational distinction is simple: being affected does not prove compromise, and being patched does not prove the system was never compromised. Those are separate questions requiring separate checks.
What Cisco Talos observed after compromise
Talos describes intrusion activity involving collection and theft of sensitive configuration or credential material, deployment of web shells and tunnelling mechanisms, and additional malware or persistence activity. These findings show why a compromised management appliance can create risk beyond the FMC itself: it may expose information useful for accessing or understanding the wider network.
However, the public evidence does not establish that every exploitation case followed the same chain, that every affected FMC was compromised, or that every organization exposed to the vulnerability suffered lateral movement.
What remains unknown
Cisco and Talos have not publicly established a complete victim count, full geographic distribution or comprehensive start date for all exploitation. The public evidence also does not prove that every observed intrusion used an identical vulnerability combination. Those limits should remain separate from the confirmed facts: CVE-2026-20079 is critically severe, active exploitation is confirmed, Cisco has remediation guidance, and administrators should investigate possible compromise rather than assuming patch installation alone closes the incident.
What happens next
Cisco has announced a Secure Firewall hardening release for September 16, 2026. That is the next scheduled material checkpoint for this article. The page should also be reviewed earlier if Cisco changes affected-version guidance, publishes new indicators of compromise, revises recovery instructions or discloses materially broader exploitation.
Verification note: ThePulseSignal reviewed Cisco’s security advisory, Cisco Talos exploitation findings and Cisco’s announced September 16 hardening checkpoint. The article distinguishes vendor-confirmed facts from unresolved campaign scope and does not infer compromise from exposure alone.



