Description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. 

This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 
Published: 2026-03-04
Score: 10 Critical
EPSS: 37.7% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the web interface of Cisco Secure Firewall Management Center creates an improper system process at boot time, enabling an attacker to send crafted HTTP requests that bypass authentication and execute scripts with root privileges. This vulnerability is a CWE-288 improper authorization flaw, permitting an unauthenticated user to gain full control over the firewall device.

Affected Systems

The affected product is Cisco Secure Firewall Management Center (FMC) software. Specific version information is not provided in the available data.

Risk and Exploitability

The CVSS score of 10 and an EPSS score of <1% indicate a high severity but a low probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be the FMC web interface, which requires unauthenticated access and no special privileges. An attacker must craft HTTP requests to trigger the unintended authentication bypass and execute scripts with root privileges.

Generated by OpenCVE AI on July 28, 2026 at 13:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Cisco's official patch or software update that addresses the authentication bypass flaw in FMC.
  • Restrict the FMC web interface to trusted management networks or VPN, eliminating direct exposure to untrusted networks.
  • Enforce limiting FMC management privileges to a minimal set of administrators and requiring multi-factor authentication.

Generated by OpenCVE AI on July 28, 2026 at 13:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow&nbsp;root access to the device.&nbsp;
Title Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Authentication Bypass in Cisco Secure Firewall Management Center Allows Remote Root Access

Thu, 16 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Authentication Bypass in Cisco Secure Firewall Management Center Allows Remote Root Access

Mon, 13 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Cisco Secure FMC Web Interface Enabling Unauthenticated Root Access

Sun, 12 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Cisco Secure FMC Web Interface Enabling Unauthenticated Root Access

Sat, 11 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Web Interface Authentication Bypass in Cisco Secure Firewall Management Center Allowing Root Access

Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Web Interface Authentication Bypass in Cisco Secure Firewall Management Center Allowing Root Access

Wed, 17 Jun 2026 06:00:00 +0000

Type Values Removed Values Added
Title Root Access via Authentication Bypass in Cisco Secure Firewall Management Center

Tue, 16 Jun 2026 11:45:00 +0000

Type Values Removed Values Added
Title Root Access via Authentication Bypass in Cisco Secure Firewall Management Center

Tue, 02 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Cisco FMC Allows Root Access

Wed, 06 May 2026 16:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Cisco FMC Allows Root Access

Sat, 02 May 2026 08:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Cisco Secure Firewall Management Center Web Interface

Wed, 29 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Cisco Secure Firewall Management Center Web Interface

Wed, 22 Apr 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Authentication Bypass in Cisco Secure Firewall Management Center Leading to Root Access

Thu, 16 Apr 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Authentication Bypass in Cisco Secure Firewall Management Center Leading to Root Access

Thu, 05 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Mar 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Management Center
Vendors & Products Cisco
Cisco secure Firewall Management Center

Wed, 04 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Secure Firewall Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-07-29T16:22:08.909Z

Reserved: 2025-10-08T11:59:15.363Z

Link: CVE-2026-20079

cve-icon Vulnrichment

Updated: 2026-03-05T14:06:30.378Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-04T18:16:24.230

Modified: 2026-06-17T10:17:02.507

Link: CVE-2026-20079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T13:15:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel