DIRAS TAKE
Urgent: this is a full pre-auth root compromise and CISA added it to the Known Exploited Vulnerabilities catalog with a mandatory remediation date, so treat exposed FMC/SCC management interfaces as high priority for mitigation.
What is CVE-2026-20079?
Unauthenticated remote attackers can bypass authentication on Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management to run scripts and gain root on the appliance (CVE-2026-20079). Affected builds are multiple 7.x releases listed by the vendor; all affected entries show no fixed version at this time. Exploitation requires only network access to the device’s management interface and specially crafted HTTP requests; no valid account or user interaction is required. The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.0.0 | |
| 7.x | 7.0.0.1 | |
| 7.x | 7.0.1 | |
| 7.x | 7.1.0 | |
| 7.x | 7.0.1.1 | |
| 7.x | 7.1.0.1 | |
| 7.x | 7.0.2 | |
| 7.x | 7.2.0 | |
| 7.x | 7.0.2.1 | |
| 7.x | 7.0.3 |
Is CVE-2026-20079 being exploited?
CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on 2026-09-09 and federal agencies were required to remediate by 2026-09-12; public exploit code is also available.
How to fix CVE-2026-20079
- Immediately restrict network access to FMC and SCC management interfaces (block internet access, limit to trusted management subnets or VPN).
- Follow Cisco’s guidance and apply any vendor mitigations; if no patch is available, consider disabling affected services or taking the device offline until fixed.
- Monitor device logs and command execution for signs of compromise and isolate any systems showing anomalous activity.
- Prepare for incident response and forensic collection per CISA guidance if compromise is suspected.
Frequently asked questions
Is CVE-2026-20079 being actively exploited?
CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on 2026-09-09, and public exploit code is available.
Which Cisco Secure Firewall Management Center and Security Cloud Control versions are affected by CVE-2026-20079?
Multiple 7.x branch builds are listed as affected; the vendor’s affected list shows several 7.0 and 7.1/7.2 builds with no fixed versions reported.
Is there a patch for CVE-2026-20079?
No fixed versions are listed in the vendor’s affected data at this time; follow Cisco’s published mitigations and restrict exposure until a patch is released.
Does CVE-2026-20079 require authentication?
No — the vulnerability allows unauthenticated, remote attackers to bypass authentication and execute scripts on the affected management appliances.
References
- nvd.nist.gov/vuln/detail/CVE-2026-20079
- cve.org/CVERecord?id=CVE-2026-20079
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20079
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026