CVE-2026-20079 – Cisco Secure Firewall Management Center (FMC)

CVSS 10 CRITICAL Critical - Same Day Deployment

“A management interface should defend the network—not become its weakest point.”

Cisco has released a security update for Cisco Secure Firewall Management Center (FMC) to address a critical vulnerability in the web interface. The flaw stems from an improperly created system process during boot, allowing an unauthenticated remote attacker to bypass authentication and execute scripts that can obtain root access to the underlying operating system by sending crafted HTTP requests. The CVSS score is 10.0, which is Critical severity.

The update corrects the affected system process and prevents unauthenticated attackers from leveraging the web interface to gain root-level access. No verified public proof-of-concept code or real-world exploitation has been confirmed for this vulnerability.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-288
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.