CVE-2026-20079 is a maximum-severity (CVSS 10.0) authentication-bypass vulnerability in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control Firewall Management software. It allows an unauthenticated remote attacker to execute scripts and commands as root on affected devices by sending crafted HTTP requests to the web interface. Cisco confirmed active exploitation (PSIRT aware from August 2026; indicators from a July advisory suggest the related static-credential flaw CVE-2026-20316 may have been used in the same attacks as early as 23 July). Cisco added it to its KEV catalogue on 9 September 2026, ordering federal civilian agencies to patch by 12 September. There is no workaround; customers must upgrade to the latest software release.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-20079 |
| Type | Authentication bypass โ RCE as root |
| CVSS | 10.0 |
| Exploited | In the wild (Aug 2026; possibly Jul 2026) |
| KEV added | 2026-09-09 |
| Source | Cisco / CISA โ Tier 1/4 |