Build1 publisher2 min readPublished
Cisco's CVSS 10 firewall-manager bypass is now being exploited to run code as root
Cisco confirmed on September 9 that attackers are exploiting a CVSS 10.0 bypass in its Firewall Management Center to run code as root. CISA added it to its Known Exploited Vulnerabilities list the same day, with a three-day deadline for federal agencies.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A companion flaw supplied the initial foothold that the CVSS 10.0 bug then escalated to root in the intrusions Cisco observed, chaining a low-severity issue into full compromise.
- Cisco Talos split the observed activity into three distinct clusters, each with different tooling and goals.
- A third cluster behaved like a ransomware affiliate, logging in with static credentials, running living-off-the-land reconnaissance, disabling endpoint protection and delivering Qilin.
- VulnCheck counted roughly 300 to 700 internet-exposed FMC instances back in March 2026, a figure it has not refreshed, so it is a stale lower bound rather than current exposure.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure FMC holds the fleet's policy, its firewall registrations, its centralized logs and its credentials, so root on one appliance reaches every firewall it governs.
- constraint Because the flaw is independent of configuration, defenders cannot scope the risk by asking which feature is enabled; the fleet divides only into patched and unpatched.
- cost Any site that left March's patch unapplied sat open for about four months before the exploitation Cisco describes.
Cisco published the advisory for CVE-2026-20079, filed as cisco-sa-onprem-fmc-authbypass-5JPp45V2, in March after an internal researcher, Brandon Sakai, found the flaw. [2] The exploitation it now describes came months later. [1] The bug affects Cisco Secure Firewall Management Center software and the Firewall Management component of Cisco Security Cloud Control. [5]
A crafted HTTP request to the management interface is enough to trigger it. [7] Cisco describes the root cause as an improperly implemented system process created at startup. The process exists from boot, and an unauthenticated request can drive it into executing code, which Cisco calls a different shape from a parser bug. [10]
The second flaw in the chain, CVE-2026-20316, was a set of static, hardcoded low-privilege credentials scored 5.3, fixed on 29 July and added to KEV the same day. [12]
One cluster planted home.jsp in the CSM Tomcat webroot alongside cmd.jar, a command executor, and used the built-in OmniQuery.pl to pull authentication data. [15] The cluster Talos links to Sandworm with high confidence chained both CVEs, rewrote license.tmp, opened a netcat reverse shell, and deployed a Linux ELF build of Cyclops Blink, a malware family better known from routers, with capabilities for credential theft, command execution, file transfer and packet capture. [16]
Cisco's detection guidance is to hunt for the temporary files these clusters leave. In expert mode, run `zgrep "package_info.*license" /var/log/messages*`; a match on /var/tmp/license.tmp is a strong signal. [18]
One date in the public record does not line up. At least one circulating indicator carries a timestamp of 23 July, ahead of the August exploitation window Cisco describes, because indicators arrive from different collection systems with different clocks. [20]
The remedy is a software update. Cisco lists fixed releases on the 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 branches, plus a combined hardening bundle in the week of 14 September. [21]
What to watch
- An updated internet-exposure count, since VulnCheck's 300 to 700 figure still dates to March 2026.
- Whether Talos adds clusters or raises confidence beyond the three attributions in the current record.
- Whether the 23 July indicator date gets reconciled with the August exploitation window Cisco describes.