Authentication bypass using an alternate path or channel in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2026-20079
Published: March 4, 2026 / Updated: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to an improper system process that is created at boot time. A remote non-authenticated attacker can bypass authentication process in the web interface and execute arbitrary code on the system with root privileges.