VULNERABILITY OVERVIEW
A CVSS 10.0 authentication bypass in the Cisco FMC web interface caused by an improper system process created at boot time, allowing an unauthenticated remote attacker to execute arbitrary script files with root privileges via crafted HTTP requests. Cisco updated its advisory on July 29, 2026 to share the same IOC (/var/tmp/license.tmp) as the actively exploited CVE-2026-20316, strongly suggesting a chaining scenario in ongoing attacks. No workarounds exist; only a full software upgrade remediates the flaw. VulnCheck published a detailed technical analysis of the exploit development process, and public PoC code is available.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
Cisco Secure FMC Software all versions prior to fixed releases (7.x, 7.7.x)CITATIONS
- → https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20079/
- → https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
- → https://www.vulncheck.com/blog/cisco-fmc-auth-bypass-cve-2026-20079
- → https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-auth-bypass
- → https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-021/