Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

CVE-2026-20079 -- CVSS 10.0 Vulnerability Briefing

CVE-2026-20079 | CVSS 10.0 (Critical) | Exploit: PoC available

What Is It

CVE-2026-20079 is a critical authentication bypass and remote code execution vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software.

Technical Detail

The vulnerability is caused by an improper system process created during device boot. An unauthenticated remote attacker can send crafted HTTP requests to an affected FMC device to bypass authentication and execute script files. Successful exploitation can provide root-level access to the underlying operating system, resulting in full device compromise.

Exploitation Status

A proof of concept is available. CISA has not listed this vulnerability in the Known Exploited Vulnerabilities catalog, and active exploitation in the wild has not been confirmed.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Treat this as an immediate patching priority because exploitation may result in unauthenticated root access. Apply Cisco-provided security updates or move affected FMC deployments to a Cisco-supported fixed release as soon as available. Until remediation is complete, restrict access to the FMC web interface to trusted administrative networks, do not expose management interfaces directly to the internet, and use network access controls to limit HTTP access to authorized administrators. Monitor FMC web-interface logs and host telemetry for unexpected HTTP requests, unauthorized script execution, new processes, or other indicators of root-level activity. No vendor workaround is confirmed in the available information.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →