CVE-2026-20079
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on a...
Affects 0 products across 3 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software allows unauthenticated remote attackers to bypass authentication and execute script files, leading to root access.
BSID: BS-2026-GLOBAL-063080-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-20079?
What is the CVSS score for CVE-2026-20079?
Is CVE-2026-20079 actively exploited?
How do I remediate CVE-2026-20079?
What systems are affected by CVE-2026-20079?
| CVE ID | CVE-2026-20079 |
|---|---|
| BSID | BS-2026-GLOBAL-063080-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2026-03-04 |
| Last Modified | 2026-09-16 |
| ICS Relevance | 65% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from an improper system process created at boot time, which can be exploited by an attacker to execute arbitrary scripts and gain root access to the underlying operating system.
Exploitation Likelihood: CRITICAL
| CISA KEV | ● Active Exploitation Confirmed (added 2026-09-09) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
AI Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | ed94c5e4e329b080f840ab52e4182ba8d5deca3edd5384c7c501e07a3f4fbb467f1ef58fc03fcf892bd15f1cbef43958d5b30d93c6e096bf9b3d99cc327cfa69 |
This Vulnerability Is Being Actively Exploited
CVE-2026-20079 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.
Create a free account →