CVE-2026-20079, a maximum-severity authentication bypass in Cisco Secure Firewall Management Center (FMC), was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026, confirming active exploitation. NVD scores the flaw CVSS 3.1 base 10.0 — the ceiling of the scale — network-exploitable, no privileges or user interaction required.
What the vulnerability does
NVD classifies CVE-2026-20079 under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). Per NVD’s description, the flaw exists in Cisco Secure Firewall Management Center’s web interface and stems from an improper system process created at boot time; an unauthenticated remote attacker can send crafted HTTP requests to bypass authentication and execute scripts and commands with root access to the underlying operating system.
The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) confirms a network-reachable flaw requiring no authentication and no user interaction, with high impact to confidentiality, integrity, and availability, and a changed scope — consistent with an authentication-bypass primitive that leads directly to root-level access on the management appliance.
Why it’s on KEV
CISA added CVE-2026-20079 to the KEV catalog on September 9, 2026, which under Binding Operational Directive (BOD) 26-04 requires federal civilian agencies to apply mitigations by CISA’s specified deadline based on the assessed risk. Cisco’s own advisory (cisco-sa-onprem-fmc-authbypass-5JPp45V2, linked from NVD’s reference data) carries the vendor’s remediation guidance; Cisco Talos has also published analysis of ongoing exploitation. CISA’s KEV entry directs affected organizations to that guidance and to evaluate each asset’s internet exposure directly rather than publishing a fixed remediation timeline of its own.
What we don’t yet have
Our data pipeline has not yet corroborated this record with a second independent source for most fields — NVD and CISA KEV agree on the CWE classification, but CVSS scoring and the vulnerability description each currently trace to only one contributing source, so we’re marking overall confidence medium, not high. We also don’t yet have an EPSS exploitation-probability score for this CVE (a gap in what we’ve ingested, not a confirmed absence) or a specific exploit-availability classification beyond the KEV listing and Talos’s public write-up of ongoing exploitation.
Why this matters
An unauthenticated, pre-boot-process authentication bypass leading to root access on a firewall management appliance is a severe finding even by KEV standards — FMC doesn’t just sit at the perimeter, it centrally administers the firewalls that do, so a successful exploit can hand an attacker root access to the console that controls an organization’s entire firewall fleet. Note that NVD’s published date for this CVE is March 4, 2026 — over six months before its September 9 KEV addition — meaning this is a previously known flaw whose exploitation status changed, not a newly disclosed one; organizations that deferred patching should treat the KEV addition as the signal that deferral is no longer defensible.
CVE-2026-20079 was added to KEV on the same day, September 9, 2026, as CVE-2026-19490, a CVSS 9.8 NetScaler authentication bypass we covered separately — and both share the same underlying CWE-288 classification (Authentication Bypass Using an Alternate Path or Channel). Two independent perimeter/management-plane auth-bypass flaws landing on KEV the same day is a useful signal for prioritization: if your environment runs both product families, neither can wait for the other’s patch cycle.
Frequently Asked Questions
What is CVE-2026-20079? A maximum-severity (CVSS 10.0) authentication bypass in Cisco Secure Firewall Management Center’s web interface, tracked under CWE-288, that leads to root access on the affected device.
Is CVE-2026-20079 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 9, 2026, and Cisco Talos has published its own analysis of ongoing exploitation.
What should Cisco FMC administrators do? Apply Cisco’s fix per advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 and evaluate internet-facing exposure immediately, consistent with CISA’s BOD 26-04 guidance for KEV-listed vulnerabilities.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 11, 2026. See more vulnerability intelligence.