CVE-2026-20079 – Cisco Secure Firewall Management Center (FMC)
“A management interface should defend the network—not become its weakest point.”
Cisco has released a security update for Cisco Secure Firewall Management Center (FMC) to address a critical vulnerability in the web interface. The flaw stems from an improperly created system process during boot, allowing an unauthenticated remote attacker to bypass authentication and execute scripts that can obtain root access to the underlying operating system by sending crafted HTTP requests. The CVSS score is 10.0, which is Critical severity.
The update corrects the affected system process and prevents unauthenticated attackers from leveraging the web interface to gain root-level access. No verified public proof-of-concept code or real-world exploitation has been confirmed for this vulnerability.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-288