In plain language
What this advisory means
Cisco Secure Firewall Management Center contains a critical authentication-bypass vulnerability. An attacker who can reach its web interface could send specially crafted HTTP requests without signing in, run scripts or commands, and obtain root-level access to the underlying operating system. Restricting the management interface from the public internet reduces exposure but does not fix the vulnerability.
Technical explanation
How the issue affects the environment
CVE-2026-20079 (CWE-288) results from an improper system process created at boot time. A remote, unauthenticated attacker can exploit the FMC web interface with crafted HTTP requests, bypass authentication, and execute script files and commands as root. Cisco assigns a CVSS 3.1 base score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The issue affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management regardless of device configuration. Cisco states that Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software, and Security Cloud Control formerly known as Defense Orchestrator are not affected.
Operational impact
Why teams should care
Successful exploitation gives an unauthenticated remote attacker root access to the management device, allowing scripts and commands to be executed with complete privileges. Cisco rates the potential confidentiality, integrity, and availability impact as high and classifies the vulnerability as Critical.
Immediate action
For Cisco Secure FMC, obtain and install the Cisco hot fix corresponding to the deployed release from the Cisco Software Center. Use Cisco's Software Checker or contact Cisco TAC to confirm exposure and the appropriate fixed software. If exploitation is suspected, contact Cisco TAC for recovery assistance and rotate all user credentials, keys, and certificates on the FMC device. Cisco SCC Firewall Management has already been updated by Cisco and requires no user action.
Affected and fixed releases
Temporary risk reduction
Cisco states that no workaround addresses this vulnerability. Keeping the FMC management interface off the public internet reduces the attack surface, but this is only an exposure-reduction measure and not a fix.
Evidence and validation checklist
- Inventory Cisco Secure FMC deployments and record their installed software releases.
- Confirm whether each FMC management web interface is reachable from the public internet.
- Use Cisco's Software Checker or the advisory's hot-fix table to identify the applicable update.
- In FMC expert mode, run: cat /var/log/messages | grep license
- Review the output for references to /var/tmp/license.tmp; Cisco states that this may indicate exploitation.
- If exploitation is suspected, contact Cisco TAC for recovery assistance and rotate all FMC user credentials, keys, and certificates.
- Verify that the applicable Cisco hot fix has been installed successfully.
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
