CVE-2026-20079
published 2026-03-04CVE-2026-20079: A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass…
PriorityP190critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EXPLOIT
EPSS
38.70%
98.4th percentile
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlGET /help/about.cgi HTTP/1.1
cookieCGISESSID=csm_processes
path/help/about.cgi
otherhtml:"BackdraftSyncIntegration"
- →Authentication bypass is triggered by sending a crafted HTTP GET request to /help/about.cgi with the cookie CGISESSID=csm_processes. A 200 response containing 'Cisco Secure Firewall Management Center', 'Model', 'OS', and 'Hostname' confirms successful bypass.
- →Without the magic cookie, the endpoint returns HTTP 302 with body containing 'Invalid session ID'. With the cookie CGISESSID=csm_processes, the endpoint returns HTTP 200 with device info, confirming unauthenticated access.
- →Shodan fingerprint for exposed Cisco FMC instances vulnerable to CVE-2026-20079 uses the HTML string 'BackdraftSyncIntegration'.
- →The vulnerability is rooted in an improper system process created at boot time; detection should focus on anomalous unauthenticated HTTP requests to CGI endpoints on Cisco FMC web interfaces. ↗
- ·No workarounds are available for this vulnerability; patching is the only remediation. ↗
- ·At time of advisory publication, Cisco PSIRT had no evidence of active exploitation or public PoC code. ↗
- ·The Nuclei template uses a two-step flow: first confirm the endpoint redirects unauthenticated requests (HTTP 302 + 'Invalid session ID'), then confirm bypass succeeds with the magic cookie (HTTP 200 + device info strings). Both conditions must be met for a verified positive.
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
vendor_cisco·2026-03-05·CVSS 10.0
CVE-2026-20079 [CRITICAL] CWE-288 Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerabili
Cisco
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20079 Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-288, CWE-
GHSA
GHSA-mv8w-c2qv-cgrg: A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypa
ghsa_unreviewed·2026-03-04
CVE-2026-20079 [CRITICAL] CWE-288 GHSA-mv8w-c2qv-cgrg: A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypa
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
No detection rules found.
Nuclei
Cisco Secure Firewall Management Center - Authentication Bypass
nuclei·CVSS 10.0
CVE-2026-20079 [CRITICAL] Cisco Secure Firewall Management Center - Authentication Bypass
Cisco Secure Firewall Management Center - Authentication Bypass
Cisco Secure Firewall Management Center Software contains an authentication bypass caused by improper system process creation at boot, letting unauthenticated remote attackers execute scripts and gain root access, exploit requires crafted HTTP requests.
Template:
id: CVE-2026-20079
info:
name: Cisco Secure Firewall Management Center - Authentication Bypass
author: theamanrawat
severity: critical
description: |
Cisco Secure Firewall Management Center Software contains an authentication bypass caused by improper system process creation at boot, letting unauthenticated remote attackers execute scripts and gain root access, exploit requires crafted HTTP requests.
impact: |
Unauthenticated remote attackers can gain root access
Bleepingcomputer
Cisco flags more SD-WAN flaws as actively exploited in attacks
blogs_bleepingcomputer·2026-03-05·CVSS 5.4
[MEDIUM] Cisco flags more SD-WAN flaws as actively exploited in attacks
## Cisco flags more SD-WAN flaws as actively exploited in attacks
## Sergiu Gatlan
Cisco has flagged two Catalyst SD-WAN Manager security flaws as actively exploited in the wild, urging administrators to upgrade vulnerable devices.
Catalyst SD-WAN Manager (formerly vManage) is network management software that enables admins to monitor and manage up to 6,000 Catalyst SD-WAN devices from a single centralized dashboard.
"In March 2026, the Cisco PSIRT became aware of active exploitation of the vulnerabilities that are described in CVE-2026-20128 and CVE-2026-20122 only," the company warned in an update to a February 25 advisory.
"The vulnerabilities that are described in the other CVEs in this advisory are not known to have been compromised. Cisco strongly recommends that customers upgr
Bleepingcomputer
Cisco warns of max severity Secure FMC flaws giving root access
blogs_bleepingcomputer·2026-03-04·CVSS 10.0
[CRITICAL] Cisco warns of max severity Secure FMC flaws giving root access
## Cisco warns of max severity Secure FMC flaws giving root access
## Sergiu Gatlan
Cisco has released security updates to patch two maximum-severity vulnerabilities in its Secure Firewall Management Center (FMC) software.
Secure FMC is a web or SSH-based interface for admins to manage Cisco firewalls and configure application control, intrusion prevention, URL filtering, and advanced malware protection.
Both vulnerabilities can be exploited remotely by unauthenticated attackers: the authentication bypass flaw ( CVE-2026-20079 ) allows attackers to gain root access to the underlying operating system, while the remote code execution (RCE) vulnerability ( CVE-2026-20131 ) lets them execute arbitrary Java code as root on unpatched devices.
"An attacker could exploit this vulnerability by
Greynoiseio
NoiseLetter March 2026
blogs_greynoiseio
NoiseLetter March 2026
Events, events… and yes, even more events. 🌍 GreyNoise has been on the move. March kept us busy with stops at eCrimes in London and SecIT in Hanover—but we’re just getting started. Over the next few months, we’ll be hitting the road for CrowdStrike CrowdTours across eight cities, heading to Glasgow to speak and sponsor CyberUK, and making our way to Tampa for H-ISAC. If you’ll be at any of these (or nearby), we’d love to connect.
And while we’ve been racking up miles, we haven’t slowed down on the research front. We’ve just released some exciting new findings—with even more coming in the next few weeks—so keep an eye out.
Thanks, as always, for being part of the GreyNoise community.
Featured
About this new report
Every enterprise firewall processes traffic from residential IP space. T
2026-03-04
Published