Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [cve, cisco, secure-fmc, authentication-bypass, kev, active-exploitation] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, financial-services] ยท au_impact: true

CVE-2026-20079 is a maximum-severity (CVSS 10.0) authentication-bypass vulnerability in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control Firewall Management software. It allows an unauthenticated remote attacker to execute scripts and commands as root on affected devices by sending crafted HTTP requests to the web interface. Cisco confirmed active exploitation (PSIRT aware from August 2026; indicators from a July advisory suggest the related static-credential flaw CVE-2026-20316 may have been used in the same attacks as early as 23 July). Cisco added it to its KEV catalogue on 9 September 2026, ordering federal civilian agencies to patch by 12 September. There is no workaround; customers must upgrade to the latest software release.

Attribute Detail
CVE CVE-2026-20079
Type Authentication bypass โ€” RCE as root
CVSS 10.0
Exploited In the wild (Aug 2026; possibly Jul 2026)
KEV added 2026-09-09
Source Cisco / CISA โ€” Tier 1/4

Source