In plain language
What this advisory means
A security flaw in Cisco Secure Firewall Management Center (FMC) software lets attackers remotely bypass login controls and run harmful scripts. This could let them take full control over the system behind the firewall. The issue exists because a system process starts incorrectly when the device boots. Attackers can exploit it by sending specially crafted web requests to the device. If your firewall management interface isn’t accessible from the internet, the risk is lower. Cisco has released updates to fix this problem, but there are no other workarounds.
Technical explanation
How the issue affects the environment
The vulnerability arises from an improper system process initiated at boot time in Cisco Secure Firewall Management Center (FMC) software. It allows an unauthenticated remote attacker to bypass the web interface's authentication mechanism. Exploitation occurs via crafted HTTP requests that enable the attacker to execute arbitrary scripts on the affected device. Successful attack results in root-level access to the underlying operating system, enabling full control over the device. This compromises confidentiality, integrity, and availability with a CVSS base score of 10.0. Disabling public internet access to the FMC management interface reduces the attack surface but does not eliminate the vulnerability. Cisco has issued hotfixes and software updates to remediate the issue, but no viable workarounds exist.
Operational impact
Why teams should care
This vulnerability is critical because it permits attackers to gain root access without authentication, threatening all managed network security controls. Attackers could execute any command on the firewall management system, potentially leading to full network compromise, unauthorized data access or modification, disruption of security monitoring, and loss of control over firewall policies. Organizations with internet-exposed FMC interfaces are at the highest risk. Immediate patching is essential to maintain network security and compliance.
Immediate action
Cisco strongly recommends installing the provided hotfixes and updated software releases that address this vulnerability. Customers should download updates from the Cisco Software Center and apply them promptly. For Cisco Security Cloud Control Firewall Management, updates have been deployed by Cisco automatically. Maintain proper device access controls, restrict external access to the FMC management interface where possible, and monitor system logs for indications of compromise as advised. Engage Cisco Technical Assistance Center for recovery assistance if exploitation is suspected.
Affected and fixed releases
Temporary risk reduction
No workarounds are available to mitigate this vulnerability. Reducing the attack surface by restricting or disabling public internet access to the FMC management interface may lower risk but does not fix the vulnerability.
Evidence and validation checklist
- Cisco PSIRT official advisory published March 4, 2026, last updated August 3, 2026
- CVE assigned CVE-2026-20079 with a CVSS score of 10.0
- Detailed explanation of attack vector involving crafted HTTP requests to FMC web interface
- No known workarounds; recommended software updates and hotfixes listed
- Indicators of compromise detection methodology described
- No known public exploits or active exploitation as per Cisco PSIRT
- Part of March 2026 Cisco Secure Firewall bundled security advisories
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
