Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

A security flaw in Cisco Secure Firewall Management Center (FMC) software lets attackers remotely bypass login controls and run harmful scripts. This could let them take full control over the system behind the firewall. The issue exists because a system process starts incorrectly when the device boots. Attackers can exploit it by sending specially crafted web requests to the device. If your firewall management interface isn’t accessible from the internet, the risk is lower. Cisco has released updates to fix this problem, but there are no other workarounds.

Published 3/8/2026, 5:27:46 pmVerified 4/8/2026, 9:52:01 pmRevision 5
Cisco critical network security advisory visual

In plain language

What this advisory means

A security flaw in Cisco Secure Firewall Management Center (FMC) software lets attackers remotely bypass login controls and run harmful scripts. This could let them take full control over the system behind the firewall. The issue exists because a system process starts incorrectly when the device boots. Attackers can exploit it by sending specially crafted web requests to the device. If your firewall management interface isn’t accessible from the internet, the risk is lower. Cisco has released updates to fix this problem, but there are no other workarounds.

Technical explanation

How the issue affects the environment

The vulnerability arises from an improper system process initiated at boot time in Cisco Secure Firewall Management Center (FMC) software. It allows an unauthenticated remote attacker to bypass the web interface's authentication mechanism. Exploitation occurs via crafted HTTP requests that enable the attacker to execute arbitrary scripts on the affected device. Successful attack results in root-level access to the underlying operating system, enabling full control over the device. This compromises confidentiality, integrity, and availability with a CVSS base score of 10.0. Disabling public internet access to the FMC management interface reduces the attack surface but does not eliminate the vulnerability. Cisco has issued hotfixes and software updates to remediate the issue, but no viable workarounds exist.

Operational impact

Why teams should care

This vulnerability is critical because it permits attackers to gain root access without authentication, threatening all managed network security controls. Attackers could execute any command on the firewall management system, potentially leading to full network compromise, unauthorized data access or modification, disruption of security monitoring, and loss of control over firewall policies. Organizations with internet-exposed FMC interfaces are at the highest risk. Immediate patching is essential to maintain network security and compliance.

Immediate action

Cisco strongly recommends installing the provided hotfixes and updated software releases that address this vulnerability. Customers should download updates from the Cisco Software Center and apply them promptly. For Cisco Security Cloud Control Firewall Management, updates have been deployed by Cisco automatically. Maintain proper device access controls, restrict external access to the FMC management interface where possible, and monitor system logs for indications of compromise as advised. Engage Cisco Technical Assistance Center for recovery assistance if exploitation is suspected.

Affected and fixed releases

Affected versionsVersions prior to corresponding hotfixes and patches as listed on Cisco software downloads page
Fixed versionsSoftware updates and hotfixes released for FMC versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 as detailed in the advisory

Temporary risk reduction

No workarounds are available to mitigate this vulnerability. Reducing the attack surface by restricting or disabling public internet access to the FMC management interface may lower risk but does not fix the vulnerability.

Evidence and validation checklist

  • Cisco PSIRT official advisory published March 4, 2026, last updated August 3, 2026
  • CVE assigned CVE-2026-20079 with a CVSS score of 10.0
  • Detailed explanation of attack vector involving crafted HTTP requests to FMC web interface
  • No known workarounds; recommended software updates and hotfixes listed
  • Indicators of compromise detection methodology described
  • No known public exploits or active exploitation as per Cisco PSIRT
  • Part of March 2026 Cisco Secure Firewall bundled security advisories

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
Cisco Secure Firewall Management Center Software | Advisory | QCS