Critical severity10.0NVD Advisory· Published Mar 4, 2026· Updated Jul 29, 2026
CVE-2026-20079
CVE-2026-20079
Description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: 7.0.0
Patches
Vulnerability mechanics
References
1News mentions
5- Cisco Patches Critical SD-WAN, IOS XE, FMC VulnerabilitiesSecurityWeek · Aug 6, 2026
- Cisco FMC static credentials exploited by attackers (CVE-2026-20316)Help Net Security · Jul 30, 2026
- Cisco Secure FMC Zero-Day Exploited in the WildSecurityWeek · Jul 30, 2026
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive DataThe Hacker News · Jul 30, 2026
- Cisco warns of FMC static credential flaw exploited in zero-day attacksBleepingComputer · Jul 29, 2026