CVE-2026-20079
CRITICAL · 10.0 KEV EPSS 75.8%KEV-listed, vendor-confirmed in-the-wild exploitation, federal deadline, mass defender response.
What: Unauthenticated authentication bypass and remote code execution in Cisco Secure Firewall Management Center (FMC) web interface, allowing root access. CVSS 10.0, EPSS 97.4th percentile.
Why it matters: KEV-listed as of 2026-09-09; Cisco confirmed active in-the-wild exploitation by nation-state and ransomware actors. CISA federal remediation deadline 2026-09-12. No workaround; patch mandatory. Originally disclosed March 2026 but exploitation began recently, triggering urgent defender triage.
Where it's seen: Major security news outlets (BleepingComputer, HelpNetSecurity), CISA/Cisco advisories, international security communities (French CERT, Dutch reporting). Consistent high-signal chatter across multiple languages and regions.
RISK: CRITICAL — Unauthenticated RCE, KEV-listed, active exploitation by sophisticated actors, zero workaround.
Description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High