Cisco Secure Firewall Management Vulnerability Allow Attackers to Bypass Authentication
## Cisco Secure Firewall Management Vulnerability
Cisco Secure Firewall Management Vulnerability
Cisco has issued an advisory regarding a critical vulnerability in its Secure Firewall Management Center (FMC) Software. This vulnerability allows an unauthenticated, remote attacker to bypass authentication and execute script files, thereby obtaining full root access to the operating system.
The flaw, identified as CVE-2026-20079, is due to an improper system process created during device boot. Exploitation can be achieved by sending specially crafted HTTP requests to the web interface of an affected FMC device. Successful exploitation provides the attacker with complete root-level control, enabling configuration modifications or further attacks using the compromised device.
This vulnerability affects all configurations of Cisco Secure FMC Software and is rated as highly critical, with a CVSS score of 10.0. Immediate attention from network administrators is required, as there are currently no workarounds or mitigations available.
Cisco has issued an advisory regarding a critical vulnerability in its Secure Firewall Management Center (FMC) Software.
Cisco recommends upgrading to the patched software versions to protect network infrastructure. Administrators should use the Cisco Software Checker tool to assess exposure and determine the appropriate upgrade path for their specific release. The vulnerability was discovered internally by security researcher Brandon Sakai.
The official security advisory was published on Tue, Mar 4, 2026, as part of the March 2026 Cisco Secure Firewall advisory package. The Cisco Product Security Incident Response Team (PSIRT) has confirmed that, to date, there are no known public announcements or exploitations of this vulnerability in the wild.
For more detailed information, refer to the official security advisory .
Based on reporting by Cyber Security News.
