CVE-2026-20079

● KEV CRITICAL

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on a...

Affects 0 products across 3 vendors.

BCS7.88
CVSS 3.110.0
EPSS88.2%
Percentile100th
PatchUnknown
KEV Added2026-09-09
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-288: CWE-288
Related Attack Patterns (CAPEC)
CAPEC-127 Directory Indexing
via CWE-288
CAPEC-665 Exploitation of Thunderbolt Protection Flaws
via CWE-288

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software allows unauthenticated remote attackers to bypass authentication and execute script files, leading to root access.

BSID: BS-2026-GLOBAL-063080-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-20079?
A critical vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software allows unauthenticated remote attackers to bypass authentication and execute script files, leading to root access.
What is the CVSS score for CVE-2026-20079?
CVE-2026-20079 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 88.2%.
Is CVE-2026-20079 actively exploited?
Yes. CVE-2026-20079 is in the CISA KEV catalog (added 2026-09-09). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-20079?
Priority: IMMEDIATE. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 PSIRT: [email protected]
What systems are affected by CVE-2026-20079?
CVE-2026-20079 affects: Cisco, Script, Scripts.
Vulnerability Details
CVE IDCVE-2026-20079
BSIDBS-2026-GLOBAL-063080-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2026-03-04
Last Modified2026-09-16
ICS Relevance65%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from an improper system process created at boot time, which can be exploited by an attacker to execute arbitrary scripts and gain root access to the underlying operating system.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cisco — —
Script — —
Scripts — —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 207 Days
CISA KEV● Active Exploitation Confirmed (added 2026-09-09)
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashed94c5e4e329b080f840ab52e4182ba8d5deca3edd5384c7c501e07a3f4fbb467f1ef58fc03fcf892bd15f1cbef43958d5b30d93c6e096bf9b3d99cc327cfa69
Related CVEs affecting Cisco
CVE-2007-1257 10.0 The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 76... CVE-2009-1167 10.0 Unspecified vulnerability on the Cisco Wireless LAN Controller (WLC) platform... CVE-2011-0364 10.0 The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6... CVE-2011-0382 10.0 The CGI subsystem on Cisco TelePresence Recording Server devices with softwar... CVE-2011-2738 10.0 Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before ...
View all Cisco CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-20079 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.

Create a free account →