ZeroDayAlert

CVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management Added to KEV 2026-09-09 Federal due 2026-09-12 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Cisco Secure Firewall Management Center (FMC) and Cisco Security Cloud Control (SCC) Firewall Management are affected by an authentication bypass flaw. An unauthenticated, remote attacker could exploit this to execute arbitrary scripts and obtain root access to the underlying operating system. The record does not specify which versions of these products are vulnerable.

How to check whether this touches you

  • Inventory whether you run Cisco FMC or SCC Firewall Management in your environment, and note the deployment context (on-premises, cloud-hosted, or hybrid).
  • Confirm whether the management interface is reachable from untrusted networks, including the internet; check firewall rules, network segmentation, and access control lists.
  • Obtain the exact version number from the admin console or API; version fingerprints alone do not confirm patched status, as vendors may backport security fixes to older releases.
  • If you use a cloud-hosted variant, verify the service provider's patch status through their security bulletins or support portal.
  • Check your logs (described below) to see whether the vulnerability has already been exploited.

What to do

  1. Immediately restrict network access to the FMC or SCC management interface to only trusted administrative networks; use a jump host or VPN if the interface is currently internet-routable.
  2. Enable and archive all authentication logs, API logs, and script execution logs with sufficient retention to cover at least the past six months; this is critical for forensic investigation if exploitation occurred before patching.
  3. Contact Cisco support to obtain the patch timeline and version guidance specific to your deployed release; do not assume your version is unsupported.
  4. Apply the patch as soon as it becomes available, following CISA BOD 26-04 timelines for risk-based prioritisation (federal systems have a 2026-09-12 remediation due date).
  5. If no patch is available within your operational window and you cannot sufficiently restrict access, escalate to your information security and risk leadership for a decision on whether to discontinue use of the product.

If you find you were exposed

Authentication bypass vulnerabilities of this type are often discovered and exploited in the wild before public disclosure, so assume that log analysis must work backwards over months rather than weeks. Examine all authentication attempts (successful and failed) to the management interface, script execution logs, and any configuration changes or new user accounts created during the period when your system was unpatched. Log retention is your primary constraint; if you cannot retain logs for six months or longer, you may be unable to establish the full scope of exposure.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-20079 is being exploited. It cannot tell you whether Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →