The box that manages every firewall rule an organisation runs is not supposed to be the easiest way in. In Cisco Secure Firewall Management Center, right now, it is.
What the bug actually does
CVE-2026-20079 lives in how FMC handles the very first moments after a reboot. During startup, the system creates a partial session tied to its internal csm_processes account in the sfsnort.sessions database. If nobody logs in right after boot, that leftover session does not simply expire the way it should. An attacker who finds it can upgrade it into working credentials and use them to call a wide set of CGI scripts on the appliance, scripts with enough reach to execute commands as root on the underlying operating system. No password, no valid account, no user interaction. Cisco rated it a perfect 10.0 on the CVSS scale, the maximum possible score, because every precondition an attacker would normally need is simply absent.
Confirmed exploitation, not a theoretical risk
Cisco has confirmed CVE-2026-20079 is being actively exploited, and Cisco Talos is tracking campaigns that link the activity to both state-sponsored groups and ransomware operators, a combination that tells you two different tiers of attacker independently found and weaponised the same flaw. Once inside, observed post-exploitation activity includes web shells, JAR-based command executors, Netcat reverse shells, proxy tooling for pivoting deeper into the network, and credential exfiltration. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 9 and gave US federal civilian agencies until September 12 to remediate, a three-day window that reflects how much damage an attacker can do once they own the console that controls every firewall policy in the environment.
Why this one matters beyond US federal networks
FMC is not an edge device sitting behind other defences. It is the management plane, the system with the credentials, policies and visibility to touch every firewall it administers. Compromising it does not just open one hole, it hands an attacker the keys to reshape the rules protecting everything else. European organisations running Cisco Secure Firewall, particularly managed service providers who operate one FMC instance across many client environments, carry that same exposure without a US federal deadline forcing the issue. Any FMC instance reachable from the internet, or reachable from a segment an attacker could already be sitting in, should be treated as compromised until proven otherwise, not simply patched and assumed safe.
What to do now
Apply Cisco’s fix immediately, and do not stop there. Because the flaw hinges on a leftover boot-time session, a reboot without a login window closed off is what creates the opening, so review whether your FMC deployment enforces prompt authentication after any restart. Audit for the artefacts Talos has already documented: unfamiliar web shells, unexpected JAR files, reverse shell connections, and any CGI scripts invoked outside normal admin activity. If your FMC console is reachable from outside a tightly controlled management network, that exposure needs to end regardless of patch status.
If you need help auditing whether your Cisco Secure Firewall deployment has been touched, or want a second set of eyes on how your management plane is segmented from the rest of your network, contact Excello Digital. We help European IT teams find out what an attacker could already be sitting on top of, before it becomes the headline.
