CVE-2026-20079

CRITICAL(10.0)KEVLikely Exploited

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Description

CVE-2026-20079 is a maximum-severity authentication bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that allows an unauthenticated, remote attacker to obtain root access to the underlying operating system. The flaw stems from an improper system process created at boot time; by sending crafted HTTP requests to an affected device, an attacker can bypass authentication and execute script files and commands as root. Because FMC centrally manages Cisco firewall estates, compromising it means control over the policy that protects every managed firewall. With a CVSS score of 10.0, an EPSS score of roughly 76% at the 99th percentile, public exploit material and a CISA Known Exploited Vulnerabilities (KEV) listing, CVE-2026-20079 is one of the most urgent vulnerabilities currently in circulation.

KEV Information

Vendor
Cisco
Product
Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Date Added
September 9, 2026
Due Date
September 12, 2026
Required Action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0

CWEs

Affected Products

VendorProductVersion
ciscosecure firewall management center7.0.0; 7.0.0.1; 7.0.1; 7.0.1.1; 7.0.2; 7.0.2.1; 7.0.3; 7.0.4; 7.0.5; 7.0.6; 7.0.6.1; 7.0.6.2; 7.0.6.3; 7.0.7; 7.0.8; 7.0.8.1; 7.0.9; 7.1.0; 7.1.0.1; 7.1.0.2; 7.1.0.3; 7.2.0; 7.2.0.1; 7.2.1; 7.2.2; 7.2.3; 7.2.3.1; 7.2.4; 7.2.4.1; 7.2.5; 7.2.5.1; 7.2.5.2; 7.2.6; 7.2.7; 7.2.8; 7.2.8.1; 7.2.9; 7.2.10; 7.2.10.1; 7.2.10.2; 7.2.11; 7.3.0; 7.3.1; 7.3.1.1; 7.3.1.2; 7.4.0; 7.4.1; 7.4.1.1; 7.4.2; 7.4.2.1; 7.4.2.2; 7.4.2.3; 7.4.2.4; 7.4.3; 7.4.4; 7.4.5; 7.4.6; 7.4.7; 7.6.0; 7.6.1; 7.6.2; 7.6.2.1; 7.6.3; 7.6.4; 7.6.5; 7.7.0; 7.7.10; 7.7.10.1; 7.7.11; 7.7.12; 10.0.0; 10.0.1

References

Weakness Type

CWE-288: Authentication Bypass Using an Alternate Path or Channel

This weakness arises when a system that requires authentication can be reached through an alternate entry point that does not enforce the same authentication requirements, so the login is bypassed rather than broken. In CVE-2026-20079 an improper system process created at boot time exposes a path reachable through crafted HTTP requests to the FMC web interface that does not apply the interface's authentication enforcement, letting an unauthenticated attacker execute scripts and commands with root privileges.

Learn more: CWE-288 — Authentication Bypass Using an Alternate Path or Channel

Impact Analysis

CVE-2026-20079 reaches the maximum CVSS 3.1 base score of 10.0 because it is remotely exploitable over the network with low attack complexity, no authentication, no user interaction, and because its scope is CHANGED — the attack escapes the web interface and yields root on the underlying operating system. Confidentiality, integrity and availability impacts are all High: root access to an FMC appliance means reading the full firewall policy set and stored credentials, rewriting rules across every managed firewall, disabling logging, and taking the management plane offline. In practice, compromise of FMC is compromise of the network's security policy, not merely of one server, and it provides an exceptionally quiet position from which to open paths into protected segments. The EPSS score of approximately 75.8% at the 99th percentile is extraordinarily high and aligns with Cisco Talos reporting on ongoing exploitation, while CISA's KEV listing set a remediation deadline of 12 September 2026 that has already passed.

Exploit Maturity

CVE-2026-20079 has the strongest possible exploitation signals. CISA has confirmed active exploitation via its Known Exploited Vulnerabilities listing, and Cisco Talos has published a dedicated report on ongoing exploitation of FMC in the wild. Exploit material is also publicly posted to the Full Disclosure mailing list — see seclists.org/fulldisclosure/2026/Aug/80 — meaning technical detail sufficient to build a working attack is freely available. The EPSS score of approximately 75.8% sits in the 99th percentile, indicating near-certain exploitation activity, and it is one of the highest EPSS values assigned to any current enterprise vulnerability. The KEV ransomware flag is "Unknown", but with public exploit material, confirmed in-the-wild attacks and unauthenticated root access as the payoff, any exposed FMC appliance must be treated as compromised until a forensic review proves otherwise.

Remediation

  1. Follow the CISA KEV required action immediately. Apply mitigations in accordance with Cisco's instructions, comply with CISA's BOD 26-04 "Prioritizing Security Updates Based on Risk" guidance and the "Forensics Triage Requirements", and discontinue use of the product if mitigations are unavailable. The KEV due date of 12 September 2026 has passed, so any unpatched appliance is overdue.
  2. Apply Cisco's fixed software release for your FMC version. Affected releases span the 7.0.x, 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.6.x, 7.7.x and 10.0.x trains; consult Cisco advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 for the exact fixed build matching your deployment, including Security Cloud Control (SCC) Firewall Management.
  3. Remove the FMC web interface from untrusted networks right now. Because exploitation requires only crafted HTTP requests, restrict access to the management interface to a dedicated management VLAN or jump-host range and block it from the internet as an immediate containment step, before and independently of patching.
  4. Assume compromise and conduct a forensic triage. Root access leaves no reliable in-band trace, so follow CISA's Forensics Triage Requirements: capture the appliance state before changes, review web server and system logs for crafted HTTP requests and unexpected script execution, check for added accounts, cron entries, modified policies and unfamiliar processes or files, and compare deployed firewall policy against a trusted baseline. Cisco Talos has published analysis of ongoing FMC exploitation with indicators to hunt for.
  5. Rebuild and rotate where compromise cannot be excluded, then harden long term. Reimage affected FMC appliances from trusted media, rotate all administrative credentials, API keys, certificates and the shared secrets used for managed-device registration, and going forward enforce authentication consistently at the service layer for every entry point — the core CWE-288 lesson — while keeping management planes off routable networks.

Technical Details

CVE-2026-20079 is an authentication bypass using an alternate path or channel (CWE-288) in Cisco Secure Firewall Management Center: an improper system process created at boot time leaves a request path into the web interface that does not enforce the interface's authentication requirements. An attacker sends crafted HTTP requests to the affected device, reaches that process, and uses it to execute a variety of script files and commands, obtaining root access to the underlying operating system. Because the failure is architectural — which requests are authenticated at all, rather than how strongly credentials are checked — password policy, multi-factor authentication and account lockouts offer no protection whatsoever. The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H records a network-reachable, low-complexity attack with no privileges and no user interaction, a changed scope reflecting the jump from web interface to operating system, and full impact on confidentiality, integrity and availability, which together produce the 10.0 maximum score.

Frequently Asked Questions

Is CVE-2026-20079 being actively exploited?

Yes, extensively. CISA lists CVE-2026-20079 in its Known Exploited Vulnerabilities catalog, Cisco Talos has published a report on ongoing exploitation of Secure Firewall Management Center, and exploit material has been posted publicly to the Full Disclosure mailing list. Its EPSS score of about 75.8% places it in the 99th percentile, indicating near-certain attack activity.

What products are affected by CVE-2026-20079?

Cisco Secure Firewall Management Center (FMC) Software is affected across a very broad range of releases, including the 7.0.x, 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.6.x, 7.7.x and 10.0.x trains, and Security Cloud Control (SCC) Firewall Management is listed alongside it in the KEV entry. Cisco's advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 enumerates the affected and fixed builds.

How do I fix CVE-2026-20079?

Apply the fixed FMC software release for your version as listed in Cisco advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2, and immediately restrict the FMC web interface to a trusted management network. Because successful exploitation grants root, also perform a forensic triage using Cisco Talos's published indicators, and reimage the appliance and rotate all credentials and certificates if compromise cannot be excluded.

How severe is CVE-2026-20079?

CVE-2026-20079 is Critical with the maximum CVSS 3.1 base score of 10.0. It is unauthenticated, network-exploitable with low complexity, needs no user interaction, crosses a security scope boundary and delivers root access to the operating system of the appliance that manages an organisation's firewalls; with an EPSS score in the 99th percentile, public exploit material and confirmed in-the-wild exploitation, it is an emergency-priority vulnerability.

CVSS Score

10.0
CRITICAL(10.0)

EPSS Score

EPSS Score75.75%
EPSS Percentile99.5%

Dates

PublishedMarch 4, 2026
Last ModifiedSeptember 16, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.