CVE-2026-20079: Cisco Secure FMC and SCC Firewall Management Vulnerability
- Severity
- HIGH
- Affected component
- cisco-fmc (other)
- Patched version
- Not yet available
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication bypass vulnerability that could allow an unauthenticated, remote attacker to execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is being actively exploited in the wild.
What happened
CVE-2026-20079 is a high-severity vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. An unauthenticated, remote attacker could exploit this flaw to bypass authentication and execute script files on an affected device, thereby obtaining root access to the underlying operating system. Cisco has confirmed that this vulnerability is being actively exploited in the wild.
CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and has set a deadline of September 12, 2026, for Federal Civilian Executive Branch (FCEB) agencies to apply the necessary patches. Cisco has identified three distinct threat clusters exploiting this vulnerability for various malicious activities, including deploying web shells, stealing credentials, and deploying ransomware.
What to do about it
- Upgrade to the latest version of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management.
- Monitor your systems for any unusual activity or unauthorized access.
- Implement additional security measures such as network segmentation and access controls to limit the impact of potential exploitation.
- Stay informed by monitoring updates from Cisco and other trusted sources for any new information or patches related to this vulnerability.
How 0Day would have caught this
cisco-fmc is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Cisco Secure Firewall Management Center (FMC) Software or Cisco Security Cloud Control (SCC) Firewall Management, you may be affected. However, no authoritative version range has been published yet. Consult the primary sources for the latest information.
What should I do right now?
Upgrade to the latest version of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. Monitor your systems for any unusual activity and implement additional security measures.
Has this been exploited in the wild?
Yes, this vulnerability is being actively exploited in the wild.
Sources
- NCSC-2026-0076 [1.02] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
- Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
- Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
- [CISA KEV] CVE-2026-20079 — Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Organizations Warned of Cisco Secure FMC Exploitation