CISCO Security Advisory
Published Date: Not specified
CVE: CVE-2026-20079
Advisory Summary
π β οΈ CRITICAL: Cisco Secure Firewall Management Center (FMC) Auth Bypass (CVE-2026-20079)
π¨ What happened
Cisco has disclosed a Critical vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could let an unauthenticated remote attacker bypass authentication, execute script files, and ultimately obtain root access on the underlying operating system.
- Root cause: an improper system process created at boot time
- Exploitation method: sending crafted HTTP requests to the affected FMC web interface
- Outcome: ability to run scripts/commands leading to full OS compromise
π Attack surface note
Cisco states that if the FMC management interface is not exposed to the public internet, the attack surface is reducedβbut exposure still depends on how the interface is reachable (VPN, peering, misroutes, etc.).
- β Software updates released by Cisco to address the issue
- β No workaround available for this vulnerability
- CVE-2026-20079
- Severity: Critical
- ensure it is reachable only via controlled management networks
- restrict inbound via ACLs/firewall rules to admin sources only
π
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Authentication%20Bypass%20%20Vulnerability%26vs_k=1
-2026-20079
Reference: Vendor Advisory