CVE-2026-20079
Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
Description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
In plain language
AI Act nowCVE-2026-20079 is a critical Cisco Secure Firewall Management Center flaw where an attacker can remotely bypass login and run code as root—so if your business uses Cisco FMC, you should treat this as an emergency to patch.
CVE-2026-20079 is an unauthenticated remote authentication-bypass leading to remote code execution as root on Cisco Secure Firewall Management Center (FMC) by abusing a boot-time system process via crafted HTTP requests.
What to do now
- Check whether your business runs Cisco Secure Firewall Management Center (FMC) and whether the boot-time process described by Cisco is active on that appliance.
- Compare your FMC software version and configuration against Cisco’s guidance for CVE-2026-20079 (use the official advisory below).
- Patch or upgrade FMC using Cisco’s remediation steps from the advisory link, and confirm the update is applied on every affected device (including any HA pairs).
- If you cannot patch immediately, follow Cisco’s interim mitigations from the same advisory and restrict access to the FMC web interface as instructed there.
- After updating/mitigating, review system and web access logs for signs consistent with exploitation (notably requests tied to the exploit activity described by Cisco).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
- Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilitiesen-us·SecurityWeek· Patch SD-WAN rce
- Cisco FMC static credentials exploited by attackers (CVE-2026-20316)en-us·Help Net Security· Exploited Secure Firewall Management Center (FMC) network-edge
- Cisco Secure FMC Zero-Day Exploited in the Wilden-us·SecurityWeek· Exploited Cisco Secure Firewall Management Center (FMC) Software network-edge
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Dataen·The Hacker News·
- Cisco warns of FMC static credential flaw exploited in zero-day attacksen-us·BleepingComputer· Exploited Cisco Secure Firewall Management Center (FMC) Software network-edge
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20079 and every CVE in our database. Create a free account — no credit card required.
Create Free Account