DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-20079PUBLISHED: 2026-03-04
CRITICALCVE-2026-20079

Cisco FMC Authentication Bypass to Root RCE

VENDOR: Cisco//PRODUCT: Cisco Secure Firewall Management Center (FMC) Software
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PoC AVAILABLE

A CVSS 10.0 authentication bypass in the Cisco FMC web interface caused by an improper system process created at boot time, allowing an unauthenticated remote attacker to execute arbitrary script files with root privileges via crafted HTTP requests. Cisco updated its advisory on July 29, 2026 to share the same IOC (/var/tmp/license.tmp) as the actively exploited CVE-2026-20316, strongly suggesting a chaining scenario in ongoing attacks. No workarounds exist; only a full software upgrade remediates the flaw. VulnCheck published a detailed technical analysis of the exploit development process, and public PoC code is available.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSCisco Secure FMC Software all versions prior to fixed releases (7.x, 7.7.x)
  • https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20079/
  • https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
  • https://www.vulncheck.com/blog/cisco-fmc-auth-bypass-cve-2026-20079
  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-auth-bypass
  • https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-021/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn