CISA Sets Sept. 12 Deadline on Cisco's Perfect-10 Firewall Bug
Security / news
CISA Sets Sept. 12 Deadline on Cisco's Perfect-10 Firewall Bug
Cisco disclosed the authentication bypass in March with no sign of exploitation; the company confirmed active attacks in August, and CISA gave federal agencies three days to respond.
An unauthenticated remote attacker can gain root access to Cisco's Secure Firewall Management Center, provided the device's web interface is reachable over the network, through a flaw now rated 10.0 out of 10 on the CVSS severity scale.
The Cybersecurity and Infrastructure Security Agency added the bug, tracked as CVE-2026-20079, to its Known Exploited Vulnerabilities catalog on Wednesday, giving federal civilian agencies until Sept. 12 to patch it or take the device offline. Cisco's own advisory, last updated the same day, says its Product Security Incident Response Team became aware of active exploitation in August.
The flaw sits in an improper system process created at boot time in FMC's web interface, according to Cisco. A single crafted HTTP request is enough: no credentials, no user interaction, and the access that results is root on the operating system underneath the console, not just inside the application.
The timeline runs longer than the exploitation window
Cisco disclosed CVE-2026-20079 on March 4, saying at the time it had no evidence the flaw was being exploited. Log entries later examined by the company showed suspicious activity starting July 23. On July 29, Cisco disclosed a second, related flaw, CVE-2026-20316, involving static credentials on the same product line. Cisco's PSIRT confirmed active exploitation of CVE-2026-20079 in August. CISA's catalog addition, and the three-day patch window, followed on Sept. 9.
FMC is the centralized console administrators use to configure and monitor Cisco's Firepower firewalls across a network. A compromise of the console does not stop at one box: it gives an attacker the reach to disable protections on every firewall FMC manages, or a path into the networks those firewalls exist to defend.
What CVSS 10.0 actually requires here
The 10.0 score is not inflated. The vector Cisco published, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, requires no privileges and no user interaction, and pairs that with a changed scope and complete loss of confidentiality, integrity and availability, the combination CVSS reserves for its ceiling. On-premises FMC releases from the 7.0 branch through 10.0 are affected; Cisco's cloud-hosted Security Cloud Control version was already patched before the public disclosure this week.
CVE-2026-20079 was one of four vulnerabilities CISA added to the exploited catalog on Sept. 9 alone, alongside flaws in Fortinet's product line, Citrix's NetScaler and Chromium's V8 engine. The pace has not slowed this month: CISA added one exploited flaw on Sept. 4, four more on Sept. 8, four again on Sept. 9, and two MikroTik RouterOS flaws on Sept. 10. Chromium's V8 engine, which just had its sixth zero-day of 2026 patched, turns up twice on the September list under two different CVE numbers.
- Sept. 41 CVEs added
- Sept. 84 CVEs added
- Sept. 94 CVEs added
- Sept. 102 CVEs added
Source: CISA KEV catalog alerts, Sept. 4-10, 2026, accessed 2026-09-11
Cisco has published hotfixes for every affected release branch and says installing one blocks further exploitation but does not remediate a device that was already compromised. Administrators who have not patched an on-premises FMC instance since March should check logs for signs of compromise before they apply the fix, not after.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.