Authentication bypass using an alternate path or channel in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2026-20079

 

Authentication bypass using an alternate path or channel in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2026-20079

Published: March 4, 2026


Vulnerability identifier: #VU123530
CSH Severity: Critical
CVSS v4: 10 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2026-20079
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to an improper system process that is created at boot time. A remote non-authenticated attacker can bypass authentication process in the web interface and execute arbitrary code on the system with root privileges. 


Affected software

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

How to mitigate CVE-2026-20079

Install updates from vendor's website.

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - addressed in versions 7.0.9, 7.2.11, 7.4.4, 7.6.4, 7.7.12

External References

Related Security Bulletins