• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-20079: pre-auth remote code execution in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

Unauthenticated remote attackers can bypass authentication on Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management to run scripts and gain root on the appliance (CVE-2026-20079). Affected builds are multiple 7.x releases listed by the vendor; all affected entries show no fixed version at this time. Exploitation requires only network access to the device’s management interface and specially crafted HTTP requests; no valid account or user interaction is required.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
10CRITICAL
EPSS
0.8818
CWE
CWE-288
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: this is a full pre-auth root compromise and CISA added it to the Known Exploited Vulnerabilities catalog with a mandatory remediation date, so treat exposed FMC/SCC management interfaces as high priority for mitigation.

What is CVE-2026-20079?

Unauthenticated remote attackers can bypass authentication on Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management to run scripts and gain root on the appliance (CVE-2026-20079). Affected builds are multiple 7.x releases listed by the vendor; all affected entries show no fixed version at this time. Exploitation requires only network access to the device’s management interface and specially crafted HTTP requests; no valid account or user interaction is required. The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management are affected?

BRANCHAFFECTEDFIXED
7.x7.0.0
7.x7.0.0.1
7.x7.0.1
7.x7.1.0
7.x7.0.1.1
7.x7.1.0.1
7.x7.0.2
7.x7.2.0
7.x7.0.2.1
7.x7.0.3

Is CVE-2026-20079 being exploited?

CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on 2026-09-09 and federal agencies were required to remediate by 2026-09-12; public exploit code is also available.

How to fix CVE-2026-20079

  1. Immediately restrict network access to FMC and SCC management interfaces (block internet access, limit to trusted management subnets or VPN).
  2. Follow Cisco’s guidance and apply any vendor mitigations; if no patch is available, consider disabling affected services or taking the device offline until fixed.
  3. Monitor device logs and command execution for signs of compromise and isolate any systems showing anomalous activity.
  4. Prepare for incident response and forensic collection per CISA guidance if compromise is suspected.

Frequently asked questions

Is CVE-2026-20079 being actively exploited?

CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on 2026-09-09, and public exploit code is available.

Which Cisco Secure Firewall Management Center and Security Cloud Control versions are affected by CVE-2026-20079?

Multiple 7.x branch builds are listed as affected; the vendor’s affected list shows several 7.0 and 7.1/7.2 builds with no fixed versions reported.

Is there a patch for CVE-2026-20079?

No fixed versions are listed in the vendor’s affected data at this time; follow Cisco’s published mitigations and restrict exposure until a patch is released.

Does CVE-2026-20079 require authentication?

No — the vulnerability allows unauthenticated, remote attackers to bypass authentication and execute scripts on the affected management appliances.

References