Critical severity10.0CISA KEVNVD Advisory· Published Mar 4, 2026· Updated Sep 16, 2026
CVE-2026-20079
CVE-2026-20079
Description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
37.0.0+ 1 more
- (no CPE)range: 7.0.0
- (no CPE)
Patches
Vulnerability mechanics
References
4- seclists.org/fulldisclosure/2026/Aug/80nvdExploitMailing ListThird Party Advisory
- blog.talosintelligence.com/fmc-ongoing-exploitation/nvdExploitThird Party Advisory
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
21- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New StoriesThe Hacker News · Sep 17, 2026
- Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus DashboardSecurityWeek · Sep 17, 2026
- Root RCE Zero-Day in Cisco Secure Email Gateway Under Active ExploitationSecurityWeek · Sep 15, 2026
- 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops BlinkDark Reading · Sep 14, 2026
- Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploitedHelp Net Security · Sep 13, 2026
- Metasploit Wrap Up: This One Goes to Sixteen!Rapid7 Blog · Sep 11, 2026
- Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin RansomwareThe Hacker News · Sep 11, 2026
- Cisco Firewall Bugs Let in Sandworm, QilinGovInfoSecurity · Sep 10, 2026
- We've got one word for it, and it's usually the wrong oneCisco Talos Intelligence · Sep 10, 2026
- Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy MalwareCyber Security News · Sep 10, 2026
- Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)Help Net Security · Sep 10, 2026
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch DeadlineThe Hacker News · Sep 10, 2026
- Organizations Warned of Cisco Secure FMC ExploitationSecurityWeek · Sep 10, 2026
- Active exploitation of Cisco Secure Firewall Management Center vulnerabilitiesCisco Talos Intelligence · Sep 9, 2026
- Cisco CVE-2026-20079 Zero-Day Added to CISA KEV Under Active ExploitationVypr Intelligence · Sep 9, 2026
- Cisco Patches Critical SD-WAN, IOS XE, FMC VulnerabilitiesSecurityWeek · Aug 6, 2026
- Cisco FMC static credentials exploited by attackers (CVE-2026-20316)Help Net Security · Jul 30, 2026
- Cisco Secure FMC Zero-Day Exploited in the WildSecurityWeek · Jul 30, 2026
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive DataThe Hacker News · Jul 30, 2026
- Cisco warns of FMC static credential flaw exploited in zero-day attacksBleepingComputer · Jul 29, 2026
- CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA Alerts