CVE Tools

CVE-2026-20079

Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability

Published: Mar 4, 2026Updated: Jul 29, 2026 Sources: CVE List NVD BDUCWE-288

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

In plain language

AI Act now

CVE-2026-20079 is a critical Cisco Secure Firewall Management Center flaw where an attacker can remotely bypass login and run code as root—so if your business uses Cisco FMC, you should treat this as an emergency to patch.

Executive summary

CVE-2026-20079 is an unauthenticated remote authentication-bypass leading to remote code execution as root on Cisco Secure Firewall Management Center (FMC) by abusing a boot-time system process via crafted HTTP requests.

If affected, business impact
Full device takeoverComplete loss of firewall controlTheft or exposure of managed dataRansomware and persistence risk

What to do now

  1. Check whether your business runs Cisco Secure Firewall Management Center (FMC) and whether the boot-time process described by Cisco is active on that appliance.
  2. Compare your FMC software version and configuration against Cisco’s guidance for CVE-2026-20079 (use the official advisory below).
  3. Patch or upgrade FMC using Cisco’s remediation steps from the advisory link, and confirm the update is applied on every affected device (including any HA pairs).
  4. If you cannot patch immediately, follow Cisco’s interim mitigations from the same advisory and restrict access to the FMC web interface as instructed there.
  5. After updating/mitigating, review system and web access logs for signs consistent with exploitation (notably requests tied to the exploit activity described by Cisco).
Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

0 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

5

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-20079 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows