CVE-2026-20079
Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
Description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
In plain language
AI Act nowCVE-2026-20079 is a critical Cisco Secure Firewall Management Center flaw where an attacker can remotely bypass login and run code as root—so if your business uses Cisco FMC, you should treat this as an emergency to patch.
CVE-2026-20079 is an unauthenticated remote authentication-bypass leading to remote code execution as root on Cisco Secure Firewall Management Center (FMC) by abusing a boot-time system process via crafted HTTP requests.
What to do now
- Check whether your business runs Cisco Secure Firewall Management Center (FMC) and whether the boot-time process described by Cisco is active on that appliance.
- Compare your FMC software version and configuration against Cisco’s guidance for CVE-2026-20079 (use the official advisory below).
- Patch or upgrade FMC using Cisco’s remediation steps from the advisory link, and confirm the update is applied on every affected device (including any HA pairs).
- If you cannot patch immediately, follow Cisco’s interim mitigations from the same advisory and restrict access to the FMC web interface as instructed there.
- After updating/mitigating, review system and web access logs for signs consistent with exploitation (notably requests tied to the exploit activity described by Cisco).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
- InfraTrust report warns network management systems under attacken-us·BleepingComputer· Exploited Cisco Secure Firewall Management Center zero-day
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Storiesen·The Hacker News· Exploited LocalAI CL-CRI-1171
- Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboarden-us·SecurityWeek· Exploited Cisco Secure Firewall Management Center rce
- Cisco patches Secure Email Gateway zero-day exploited in attacksen-us·BleepingComputer· Exploited Cisco Secure Email Gateway zero-day
- Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitationen-us·SecurityWeek· Exploited Secure Email Gateway zero-day
- 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blinken·Dark Reading· Exploited Secure Firewall Management Center Sandworm
- Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploiteden-us·Help Net Security· Exploited F5 BIG-IP APM ransomware
- Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomwareen·The Hacker News· Exploited Secure Firewall Management Center Sandworm
- We've got one word for it, and it's usually the wrong oneen·Cisco Talos· Exploited Microsoft Defender UAT-10820
- Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)en-us·Help Net Security· Exploited Cisco Secure Firewall Management Center (FMC) Sandworm
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20079 and every CVE in our database. Create a free account — no credit card required.
Create Free Account