CVE-2026-20079 — Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
- Severity
- critical
- Product
- Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Published
- 2026-09-09
- EPSS
- 0.747
- CISA KEV
- Known exploited
- Ransomware
- Known campaign use
References and validation
- https://github.com/search?q=CVE-2026-20079&type=repositories
- https://nvd.nist.gov/vuln/detail/CVE-2026-20079
Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.