Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

Cisco Secure Firewall Management Center contains a critical authentication-bypass vulnerability. An attacker who can reach its web interface could send specially crafted HTTP requests without signing in, run scripts or commands, and obtain root-level access to the underlying operating system. Restricting the management interface from the public internet reduces exposure but does not fix the vulnerability.

Published 29/7/2026, 3:55:40 pmVerified 29/7/2026, 6:12:53 pmRevision 2
Cisco critical network security advisory visual

In plain language

What this advisory means

Cisco Secure Firewall Management Center contains a critical authentication-bypass vulnerability. An attacker who can reach its web interface could send specially crafted HTTP requests without signing in, run scripts or commands, and obtain root-level access to the underlying operating system. Restricting the management interface from the public internet reduces exposure but does not fix the vulnerability.

Technical explanation

How the issue affects the environment

CVE-2026-20079 (CWE-288) results from an improper system process created at boot time. A remote, unauthenticated attacker can exploit the FMC web interface with crafted HTTP requests, bypass authentication, and execute script files and commands as root. Cisco assigns a CVSS 3.1 base score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The issue affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management regardless of device configuration. Cisco states that Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software, and Security Cloud Control formerly known as Defense Orchestrator are not affected.

Operational impact

Why teams should care

Successful exploitation gives an unauthenticated remote attacker root access to the management device, allowing scripts and commands to be executed with complete privileges. Cisco rates the potential confidentiality, integrity, and availability impact as high and classifies the vulnerability as Critical.

Immediate action

For Cisco Secure FMC, obtain and install the Cisco hot fix corresponding to the deployed release from the Cisco Software Center. Use Cisco's Software Checker or contact Cisco TAC to confirm exposure and the appropriate fixed software. If exploitation is suspected, contact Cisco TAC for recovery assistance and rotate all user credentials, keys, and certificates on the FMC device. Cisco SCC Firewall Management has already been updated by Cisco and requires no user action.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsCisco Secure FMC 7.0 — Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar, Cisco Secure FMC 7.2 — Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar, Cisco Secure FMC 7.4 — Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar, Cisco Secure FMC 7.6 — Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar, Cisco Secure FMC 7.7 — Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar, Cisco Secure FMC 10.0 — Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar, Cisco SCC Firewall Management — Cisco has deployed the fix to its SaaS environments; no customer action is required

Temporary risk reduction

Cisco states that no workaround addresses this vulnerability. Keeping the FMC management interface off the public internet reduces the attack surface, but this is only an exposure-reduction measure and not a fix.

Evidence and validation checklist

  • Inventory Cisco Secure FMC deployments and record their installed software releases.
  • Confirm whether each FMC management web interface is reachable from the public internet.
  • Use Cisco's Software Checker or the advisory's hot-fix table to identify the applicable update.
  • In FMC expert mode, run: cat /var/log/messages | grep license
  • Review the output for references to /var/tmp/license.tmp; Cisco states that this may indicate exploitation.
  • If exploitation is suspected, contact Cisco TAC for recovery assistance and rotate all FMC user credentials, keys, and certificates.
  • Verify that the applicable Cisco hot fix has been installed successfully.

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source