CVE-2026-20079

Published Mar 4, 2026

Last updated 11 days ago

CVSS critical 10.0
Network
System
Port (80)
HTTP

Overview

Description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 
Source
psirt@cisco.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@cisco.com
CWE-288

Social media

Hype score
Not currently trending
  1. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-EDB-AWZes1i ( CVE-2026-48907 ) EGE-GH-86PDTBb ( CVE-2025-55182 ) EGE-GH-uET14Zz ( CVE-2026-20079 ) EGE-GH-voHgFaT ( CVE-2026-59310 ) EGE-GH-seDlYMs ( CVE-2026-59310 ) ..🧵👇

    @exploitgrid

    18 Aug 2026

    88 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Cisco Secure FMC zero day CVE-2026-20316 is under active exploitation. Chained with CVE-2026-20079 (CVSS 10.0 auth bypass), attackers hit root. CISA set FCEB deadline Aug 1. Still unpatched? Assume compromise. #ZeroDay #InfoSec #Cybersecurity

    @infrasecserv

    9 Aug 2026

    96 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  3. Cisco Secure Firewall Management Center = CVSS 10.0 open door. CVE-2026-20079 lets an unauth attacker send a crafted HTTP request → execute scripts → root. CVE-2026-20316 is actively exploited (static creds). Patch this weekend. No workaround. https://t.co/aiO0JUThmq

    @FaultSignal_

    7 Aug 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CISA added Cisco FMC zero-day CVE-2026-20316 to KEV, actively exploited via hard-coded creds. Chainable with CVE-2026-20079 (CVSS 10.0) for root RCE. FCEB deadline was Aug 1. If you run Firepower Mgmt Center, patch now or assume breach. #Cybersecurity #ZeroDay #CVE

    @infrasecserv

    5 Aug 2026

    89 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Cisco Secure FMC CVE-2026-20316 (static creds) + CVE-2026-20079 (CVSS 10.0, auth bypass to root) is a chained zero-day now on CISA KEV. Federal Aug 1 deadline is up. If you own FMC and have not patched, treat as compromised. #Cybersecurity #InfoSec #ZeroDay

    @infrasecserv

    3 Aug 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Cisco Secure FMC ships with a hardcoded low-priv account (CVE-2026-20316), already exploited. Same advisory reactivates a CVSS 10.0 root bypass (CVE-2026-20079), sharing an IOC. CISA deadline Aug 1. Patch now. https://t.co/6C6UrTKygC https://t.co/tMY18VWLNi #CyberSecurity htt

    @DIESEC_GmbH

    3 Aug 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Cisco FMC has a backdoor credential hard-coded into every version 7.0-10.0. CVE-2026-20316 chains with CVE-2026-20079 (CVSS 10.0) for root shell on your firewall manager. CISA KEV. Patch by August 1. https://t.co/2KicMADqIu #CiscoFMC #ZeroDay

    @DecryptionDigst

    31 Jul 2026

    68 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Cisco alerta para falhas zero-day no Secure FMC (CVE-2026-20316 e CVE-2026-20079) https://t.co/pJgdXvOkYT

    @SempreUpdate

    30 Jul 2026

    102 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CISA added Cisco FMC CVE-2026-20316 to its KEV catalog after zero-day exploitation reports. Static credentials in a low-privilege account may expose sensitive data and could chain with CVE-2026-20079 for privilege escalation. #Cisco #CISAKev #ZeroDay https://t.co/4IeAMkBcNW

    @TweetThreatNews

    30 Jul 2026

    131 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Cisco warns that CVE-2026-20316 in Secure Firewall Management Center used static credentials, enabling zero-day access to vulnerable devices. Cisco also patched CVE-2026-20079, a critical FMC auth bypass. #Cisco #CVE-2026-20316 #CVE-2026-20079 https://t.co/CxQ53TRfHf

    @TweetThreatNews

    30 Jul 2026

    234 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes