DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // cisco-sa-fmc-authbypass-CSCwt95974 // PUBLISHED 2026-08-01
Cisco PSIRTCVE-2026-20079

Cisco Secure FMC Critical Authentication Bypass Enabling Root RCE (CVE-2026-20079)

Cisco updated its advisory for CVE-2026-20079 (CVSS 10.0) on July 29, 2026 — a critical authentication bypass in Cisco Secure FMC Software caused by an improper system process created at boot time. An unauthenticated remote attacker can bypass authentication and execute arbitrary executable scripts to obtain root access via crafted HTTP requests, without requiring any credentials or prior device access. Cisco published the same /var/tmp/license.tmp indicator of compromise as for the actively exploited CVE-2026-20316, strongly suggesting these two flaws are being chained in active attacks.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
Cisco Secure FMC Software 7.0.x
CRITICAL
POC
PATCHED
Cisco Secure FMC Software 7.2.x
CRITICAL
POC
PATCHED
Cisco Secure FMC Software 7.4.x
CRITICAL
POC
PATCHED
Cisco Secure FMC Software 7.6.x
CRITICAL
POC
PATCHED
Cisco Secure FMC Software 7.7.x
CRITICAL
POC
PATCHED
Cisco Secure FMC Software 10.0.x
CRITICAL
POC
PATCHED

Apply the same Cisco Secure FMC hot fixes released for CVE-2026-20316 (covering releases 7.0, 7.2, 7.4, 7.6, 7.7, 10.0). No workarounds fully address this vulnerability. Restrict internet-facing access to the FMC management interface. Treat any FMC device as potentially compromised and conduct full forensic triage.

Same IoC as CVE-2026-20316: check for /var/tmp/license.tmp via cat /var/log/messages | grep license in expert mode. Look for the www web-service account invoking package_info.pl as root. Monitor for unauthenticated HTTP requests to the FMC management interface and unusual script execution events at boot.

EXPORT FORMATTED IOC PACKAGE
Splunk SPL · KQL · Sigma rules · Firewall blocklists — subscriber feature
SUBSCRIBE →
#
TYPE
INDICATOR
CONTEXT
FIRST SEEN
001
HASH
/var/tmp/license.tmp
Compromise Indicator File Path
2026-08-01
  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-authbypass-CSCwt95974
  • https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
  • https://nvd.nist.gov/vuln/detail/CVE-2026-20079
SHARE BRIEF:✕ Post on Xin Share on LinkedIn