🚨SEVERITY: CRITICAL — CVSS 10.0Security Advisory

TL;DR 📌

  • A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time.…
  • Highest CVSS: 10.0 (Critical).
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-20079.

What it is

CVE-2026-20079 is an authentication bypass in the web interface of Cisco Secure Firewall Management Center (FMC) Software. It carries a CVSS score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) — network-exploitable, no privileges, no user interaction, and full impact on confidentiality, integrity and availability.