Cisco Secure FMC - CVE 2026 20079 Check
A read-only check that tells you if a Cisco Secure FMC appliance needs attention for CVE-2026-20079. Cisco has confirmed in the wild exploitation as of September 2026.
What it looks for.
Whether the management interface answers.
What software version the appliance reports
Whether that train is in Cisco's hot-fix list.
Whether the audit trail shows logins for the built-in machine accounts the bypass abuses.
What to do with the results. It's all in $FmcStatusText:
-
Machine-account audit hits. Handle first. Preserve the appliance, sweep it on-box, open a Cisco TAC case. Don't patch a suspected compromise; Cisco says the hot fix may not address an existing one.
-
Affected train with a named hot fix. Remediation ticket. Apply it, then confirm on the appliance, because the reported version doesn't reliably change when a hot fix goes on.
-
Check didn't complete. Rejected credential, unreachable port, or the exception itself. Fix and re-run. Incomplete is not passing.
-
Train not listed. Confirm with the Cisco Software Checker before calling it good
The limit. This sees version state and audit records, not the web shells, persistence, or tunnels attackers leave on the FMC filesystem. A clean result narrows your list; it doesn't clear an appliance.
Cisco's remediation guidance, including the hot-fix table and the indicator-of-compromise check: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-a…