Authentication Bypass in Cisco Secure Firewall Management Center
CVE-2026-20079

10CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
4 March 2026

Badges

📈 Trended📈 Score: 2,800💰 Ransomware👾 Exploit Exists🟡 Public PoC🟣 EPSS 75%🦅 CISA Reported📰 News Worthy

What is CVE-2026-20079?

CVE-2026-20079 is a vulnerability identified in the web interface of Cisco Secure Firewall Management Center (FMC) Software, designed to provide centralized management for Cisco’s security devices. The vulnerability stems from an improper system process created at boot time, which could be exploited by an unauthenticated remote attacker. By sending specifically crafted HTTP requests to the affected device, an attacker could bypass authentication measures. This unauthorized access can enable them to execute scripts and commands, ultimately granting root access to the underlying operating system. Such a breach poses a high risk to organizations that rely on Cisco Secure Firewall Management Center for their network security, as it compromises the integrity of the security infrastructure.

Potential impact of CVE-2026-20079

  1. Unauthorized Access and Control: The vulnerability allows attackers to gain root access, leading to full control over the affected system. This can enable them to manipulate settings, access sensitive information, or install malicious programs that could compromise the entire network.

  2. Data Breaches: With root access, an attacker can extract confidential data, potentially leading to significant data breaches. This can result in financial losses, regulatory penalties, and harm to an organization’s reputation.

  3. System Compromise and Malware Deployment: An exploited vulnerability may facilitate the deployment of ransomware or other types of malware, which can disrupt services and lead to extended downtime. The presence of malware could also pave the way for further attacks on interconnected systems within the organization.

CISA has reported CVE-2026-20079

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-20079 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Cisco Secure Firewall Management Center (FMC) 7.0.0

Cisco Secure Firewall Management Center (FMC) 7.0.0.1

Cisco Secure Firewall Management Center (FMC) 7.0.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

'Sandworm' Chains Cisco Flaws to Deploy Cyclops Blink

The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.

6 days ago

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware - SwapUpdate

Ravie LakshmananSep 11, 2026Vulnerability / Malware

1 week ago

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero trust AI agents demand a different kind of security

1 week ago

References

EPSS Score

75% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 💰

    Used in Ransomware

  • 🦅

    CISA Reported

  • 📰

    First article discovered by BleepingComputer

  • 📈

    Vulnerability started trending

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.