Cisco has patched a critical vulnerability in its Secure Firewall Management Center (FMC) Software. This flaw lets unauthenticated attackers gain full root access to affected devices.
With a top CVSS score of 10.0, it poses a huge risk to enterprise networks. Cisco researcher Brandon Sakai found it during internal tests.
The problem starts in the boot process. A faulty system process opens the door for attacks. Hackers send crafted HTTP requests to the FMC web interface.
This bypasses all authentication. Attackers then run malicious scripts and take complete control of the OS. From the FMC console, they can change security rules, spy on traffic, and move deeper into networks.
This hits only on-premises FMC setups, no matter the config. No user action or credentials needed, pure remote exploit. No workarounds exist. Cloud versions and related products like ASA, FTD, and Security Cloud Control stay safe.
Cisco’s PSIRT says no wild exploits have been seen yet as of March 2026. But urgency is key to avoiding ransomware or breaches.
| Field | Information |
|---|---|
| CVE ID | CVE-2026-20079 |
| Advisory ID | cisco-sa-onprem-fmc-authbypass-5JPp45V2 |
| CVSS v3.1 Score | 10.0 (Critical) |
| CWE | CWE-288 (Authentication Bypass) |
| Bug ID | CSCwr96008 |
| Description | Web interface auth bypass from bad boot init; enables unauth remote script exec and root access. |
Fix It Now
Upgrade to a patched FMC release right away. Use Cisco’s Software Checker tool. Enter your version to find the earliest safe update.
Prioritize in your patch cycle. Test in staging first, then roll out. Monitor logs for odd HTTP traffic to the FMC interface meanwhile.
This flaw underscores boot process risks in management tools. Network admins: Check exposure today.
Impacts: Full perimeter compromise possible. Ties to MITRE ATT&CK T1190 (Supply Chain), TA0005 (Defense Evasion).
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.