PT-2026-22978 · Cisco · Cisco Secure Firewall Management Center (Fmc)

Brandon Sakai

·

Published

2026-03-04

·

Updated

2026-03-05

·

CVE-2026-20079

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Secure Firewall Management Center (FMC) Software (affected versions not specified)
Description A flaw exists in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow a remote attacker who does not need to be authenticated to bypass authentication and execute script files on a vulnerable device. This could lead to the attacker gaining root access to the underlying operating system. The issue is caused by an improperly configured system process created during startup. An attacker can exploit this by sending specially crafted HTTP requests to the affected device. Successful exploitation allows the attacker to execute scripts and commands, ultimately gaining root access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2026-20079

Affected Products

Cisco Secure Firewall Management Center (Fmc)