Cisco FMC Authentication Bypass Enables Root OS Access
CVE-2026-20079 is a CVSS 10.0 unauthenticated auth bypass in Cisco FMC with root OS access. Actively exploited; CISA KEV deadline September 12.
- Vendor
- Cisco
- Product
- Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- CVSS
- 10.0
- EPSS (exploit probability)
- 35.9%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
Cisco Secure Firewall Management Center (FMC) Software and Security Cloud Control (SCC) Firewall Management contain a CVSS 10.0 authentication bypass, confirmed actively exploited as of September 9, 2026. The flaw is documented in Cisco’s advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 and tracked at NVD.
What the vulnerability is
The flaw is an authentication bypass via an alternate path or channel. An unauthenticated, remote attacker can reach FMC or SCC through a path that sidesteps the normal authentication flow. Once past the login gate, the attacker can execute script files on the affected device and obtain root access to the underlying operating system.
Root access on an FMC or SCC instance means control over the management plane for every firewall that device administers. Policy configuration, network rule sets, traffic logs, and credentials stored on the device are all within reach.
The CVSS 10.0 score reflects the full stack of severity factors: no authentication required, no user interaction required, network-accessible attack surface, and full compromise of confidentiality, integrity, and availability at the OS level.
Exploitation status
CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on September 9, 2026. Cisco confirmed active exploitation in attacks the same day. Under BOD 26-04, federal civilian executive branch agencies must apply mitigations by September 12, 2026, a three-day window from KEV addition.
That three-day deadline is CISA’s signal that exploitation is current and not theoretical.
Affected products
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. Specific affected versions and software upgrade paths are listed in Cisco’s advisory. Cisco has not documented a workaround for the underlying authentication bypass itself.
What to do
Apply Cisco’s update. Check the advisory for your version’s upgrade path.
Prioritize patching where the FMC management interface is reachable from the internet or untrusted segments. That configuration is directly exploitable without any additional access. Deployments on isolated management VLANs or behind jump hosts face less immediate exposure, but isolation is not a substitute for patching, and the CVSS 10.0 rating warrants prompt action regardless of network architecture.
Federal agencies operating under BOD 26-04 have a hard September 12 deadline. Commercial operators have no mandatory cutoff, but confirmed active exploitation and a maximum CVSS score make delay difficult to justify.
If you cannot patch immediately, Cisco’s guidance on restricting management interface exposure can limit the attack surface while the patch window is scheduled.
Context
This is the second Cisco Secure FMC vulnerability confirmed exploited in the wild this year. CVE-2026-20316, a hardcoded credential flaw in FMC’s web interface, reached CISA’s KEV catalog on July 29, 2026. Both entries target the same management platform. Network defenders managing Cisco firewall infrastructure should treat FMC’s management interface as a high-value attack target requiring its own access controls and rapid patch cadence.
For full news coverage of this exploitation confirmation, see the 0dayNews article on CVE-2026-20079.
