CVE-2026-20079

CRITICAL NUCLEI

Cisco Secure FMC - Auth Bypass

Title source: llm

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.

Exploits (4)

github SUSPICIOUS 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-20079
nomisec WORKING POC
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2026-20079
nomisec SCANNER
by Sushilsin · poc
https://github.com/Sushilsin/CVE-2026-20079
nomisec SUSPICIOUS
by b1gchoi · poc
https://github.com/b1gchoi/CVE-2026-20079

Nuclei Templates (1)

Cisco Secure Firewall Management Center - Authentication Bypass
CRITICALVERIFIEDby theamanrawat
Shodan: html:"BackdraftSyncIntegration"

Scores

CVSS v3 10.0
EPSS 0.2026
EPSS Percentile 95.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-288
Status published
Published Mar 04, 2026
Tracked Since Mar 05, 2026