CISCO Security Advisory

Published Date: Not specified

CVE: CVE-2026-20079

Advisory Summary

πŸ” ⚠️ CRITICAL: Cisco Secure Firewall Management Center (FMC) Auth Bypass (CVE-2026-20079)

🚨 What happened
Cisco has disclosed a Critical vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could let an unauthenticated remote attacker bypass authentication, execute script files, and ultimately obtain root access on the underlying operating system.

🌐 Attack surface note
Cisco states that if the FMC management interface is not exposed to the public internet, the attack surface is reducedβ€”but exposure still depends on how the interface is reachable (VPN, peering, misroutes, etc.).

πŸ”—
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Authentication%20Bypass%20%20Vulnerability%26vs_k=1

-2026-20079

Reference: Vendor Advisory