Junglewise Threat Intelligence

CVE-2026-20079: Cisco Secure Firewall Management Center auth bypass in web interface

CVE-2026-20079 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-03-04

Technologies: Cisco Secure Firewall Management Center, Cisco Secure Firewall Management Center (FMC). Vendors: Cisco.

Executive brief

Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) contain an authentication bypass vulnerability that allows unauthenticated remote attackers to gain root access to the underlying operating system. An attacker exploiting this flaw can execute arbitrary scripts and take complete control of the device, potentially compromising all managed firewalls and security policies. This vulnerability is already being exploited in the wild.

Technical details

This vulnerability is an authentication bypass using an alternate path or channel in Cisco Secure Firewall Management Center and Security Cloud Control Firewall Management. An unauthenticated remote attacker can bypass the authentication mechanism via an alternative communication channel to execute arbitrary script files on the affected device. Successful exploitation grants root-level access to the underlying operating system, enabling complete system compromise and control of all managed security policies. The vulnerability is network-reachable and requires no user interaction or prior authentication. Active exploitation in the wild confirms this is being weaponized. Patch availability should be confirmed through Cisco security advisories.

Affected products

  • Cisco Secure Firewall Management Center (FMC)
  • Cisco Security Cloud Control (SCC) Firewall Management

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: exploited: Confirmed active exploitation in the wild

Related threats