CVE-2026-20079 -- CVSS 10.0 Vulnerability Briefing
CVE-2026-20079 | CVSS 10.0 (Critical) | Exploit: PoC available
What Is It
CVE-2026-20079 is a critical authentication bypass and remote code execution vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software.
Technical Detail
The vulnerability is caused by an improper system process created during device boot. An unauthenticated remote attacker can send crafted HTTP requests to an affected FMC device to bypass authentication and execute script files. Successful exploitation can provide root-level access to the underlying operating system, resulting in full device compromise.
Exploitation Status
A proof of concept is available. CISA has not listed this vulnerability in the Known Exploited Vulnerabilities catalog, and active exploitation in the wild has not been confirmed.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Treat this as an immediate patching priority because exploitation may result in unauthenticated root access. Apply Cisco-provided security updates or move affected FMC deployments to a Cisco-supported fixed release as soon as available. Until remediation is complete, restrict access to the FMC web interface to trusted administrative networks, do not expose management interfaces directly to the internet, and use network access controls to limit HTTP access to authorized administrators. Monitor FMC web-interface logs and host telemetry for unexpected HTTP requests, unauthorized script execution, new processes, or other indicators of root-level activity. No vendor workaround is confirmed in the available information.