Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

A security flaw in Cisco Secure Firewall Management Center lets attackers bypass login, run scripts, and gain full control of the device. This happens because a system process created at startup is vulnerable. Attackers can exploit it by sending special web requests. If your firewall’s management web interface is not publicly accessible, the risk is lower. Cisco has released software updates to fix this issue. There are no other workarounds.

Published 9/9/2026, 4:00:43 pmVerified 10/9/2026, 12:18:10 amRevision 6
Cisco critical network security advisory visual

In plain language

What this advisory means

A security flaw in Cisco Secure Firewall Management Center lets attackers bypass login, run scripts, and gain full control of the device. This happens because a system process created at startup is vulnerable. Attackers can exploit it by sending special web requests. If your firewall’s management web interface is not publicly accessible, the risk is lower. Cisco has released software updates to fix this issue. There are no other workarounds.

Technical explanation

How the issue affects the environment

Cisco Secure Firewall Management Center (FMC) suffers an authentication bypass vulnerability (CVE-2026-20079) in its web interface due to an improper system process created during boot. This allows unauthenticated remote attackers to send crafted HTTP requests that execute arbitrary scripts and commands, obtaining root-level access to the underlying operating system. This critical vulnerability scores 10.0 on CVSS v3.1 and impacts all Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management devices. Mitigation requires applying Cisco's released hot fixes or fixed software versions. No workarounds are available.

Operational impact

Why teams should care

This vulnerability allows attackers to gain root access to critical network management devices, compromising firewall controls and network security. Successful exploitation can lead to complete device takeover, loss of confidentiality, integrity, and availability, and potentially widespread network disruption and data breaches. The risk is reduced if the management interface is not exposed to the internet, but internal threat actors or lateral attackers remain a concern. Immediate remediation is required to prevent critical security failures.

Immediate action

Apply the Cisco Secure FMC hot fixes or upgraded software releases made available by Cisco to remediate the authentication bypass vulnerability. Engage Cisco Technical Assistance Center if compromise is suspected.

Affected and fixed releases

Affected versionsVersions prior to Cisco Secure FMC Hotfixing releases 7.0.9.1-3, 7.2.11.1-4, 7.4.7.1-3, 7.6.5.1-2, 7.7.12.1-2, 10.0.1.1-2
Fixed versionsCisco Secure FMC Hotfixes: GB-7.0.9.1-3, HL-7.2.11.1-4, HG-7.4.7.1-3, CY-7.6.5.1-2, AM-7.7.12.1-2, P-10.0.1.1-2

Temporary risk reduction

There are no workarounds available for this vulnerability. Limiting management interface internet exposure reduces attack surface but does not eliminate risk.

Evidence and validation checklist

  • Cisco advisory ID cisco-sa-onprem-fmc-authbypass-5JPp45V2
  • Cisco PSIRT published advisory dated March 4, 2026, updated September 9, 2026
  • CVE-2026-20079 with CVSS v3.1 base score 10.0
  • Exploitation confirmed August 2026
  • No workarounds; hot fixes released for versions 7.0 through 10.0 series
  • Advisory notes using crafted HTTP requests to bypass authentication and gain root access
  • Recommended immediate upgrade to fixed software versions

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source