Executive brief
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) contain an authentication bypass vulnerability that allows unauthenticated remote attackers to gain root access to the underlying operating system. An attacker exploiting this flaw can execute arbitrary scripts and take complete control of the device, potentially compromising all managed firewalls and security policies. This vulnerability is already being exploited in the wild.
Technical details
This vulnerability is an authentication bypass using an alternate path or channel in Cisco Secure Firewall Management Center and Security Cloud Control Firewall Management. An unauthenticated remote attacker can bypass the authentication mechanism via an alternative communication channel to execute arbitrary script files on the affected device. Successful exploitation grants root-level access to the underlying operating system, enabling complete system compromise and control of all managed security policies. The vulnerability is network-reachable and requires no user interaction or prior authentication. Active exploitation in the wild confirms this is being weaponized. Patch availability should be confirmed through Cisco security advisories.
Affected products
- Cisco Secure Firewall Management Center (FMC)
- Cisco Security Cloud Control (SCC) Firewall Management
Timeline
- 2026-09-09: disclosed
- 2026-09-09: exploited: Confirmed active exploitation in the wild