Cisco Secure Firewall Management Center Software Hit with Critical Authentication Bypass Vulnerability
A critical vulnerability, CVE-2026-20079, has been identified in Cisco Secure Firewall Management Center (FMC) Software. The issue allows an unauthenticated remote attacker to bypass authentication via crafted HTTP requests and execute scripts or commands as root on the underlying operating system.
Cisco rates the issue CVSS 3.1 10.0 Critical, indicating a high severity rating. The vulnerability was first published by Cisco on March 4, 2026, and it became aware of active exploitation in August 2026. CISA added CVE-2026-20079 to the Known Exploited Vulnerabilities catalog on September 9, 2026.
The affected product versions include Cisco Secure FMC Software (regardless of device configuration) and Cisco Security Cloud Control (SCC) Firewall Management (SaaS). However, Cisco has already deployed the fix for SCC SaaS with no customer action required. The recommended remediation is to upgrade to a first-fixed hardening release.
Cisco lists Snort rules 66075-66080 on the advisory. Discovery credit goes to Brandon Sakai of Cisco (internal security testing). Bug ID: CSCwr96008.