Priority reviewCritical

CVE-2026-20079

Cisco Cisco Secure Firewall Management Center (FMC)

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the devic...

CVSS
10
EPSS
37.7%
98.4% percentile
CISA KEV
Not listed
Published
2026.03.05
PRIORITY ASSESSMENT

Priority review

FIRST EPSS indicates an elevated probability of exploitation.

Known exploitationNot established by KEV
Exploit probability37.7%
Technical severityCVSS 10

Vulnerability overview

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the devic...

Affected product and versions

Product
Cisco Cisco Secure Firewall Management Center (FMC)
Affected versions
>= 7.0.0, >= 7.0.0.1, >= 7.0.1, >= 7.1.0, >= 7.0.1.1, >= 7.1.0.1, >= 7.0.2, >= 7.2.0, >= 7.0.2.1, >= 7.0.3, >= 7.1.0.2, >= 7.2.0.1, >= 7.0.4, >= 7.2.1, >= 7.0.5, >= 7.3.0, >= 7.2.2, >= 7.3.1, >= 7.2.3, >= 7.1.0.3
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Cisco Cisco Secure Firewall Management Center (FMC) and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-288
CVE-2026-20079 — Cisco Cisco Secure Firewall Management Center (FMC) | SECUFOCUS NOW