CVE-2026-20079

CRITICAL

Cisco Secure FMC - Auth Bypass

Title source: llm

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.

Exploits (3)

github SUSPICIOUS 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-20079
nomisec SUSPICIOUS
by b1gchoi · poc
https://github.com/b1gchoi/CVE-2026-20079
nomisec SCANNER
by Sushilsin · poc
https://github.com/Sushilsin/CVE-2026-20079

Scores

CVSS v3 10.0
EPSS 0.0019
EPSS Percentile 40.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-288
Status draft

Timeline

Published Mar 04, 2026
Tracked Since Mar 05, 2026