RaqibCTI
CVE

CVE-2026-20079

P2
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Cisco · Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Date added (CISA)
2026-09-09
Remediation due
2026-09-12
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • payload · AmateracampaignCorrelated cluster2026-09-21
  • Cyclops BlinkcampaignCorrelated cluster2026-09-10

Description

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

Source: NVD ↗ · CISA KEV Catalog ↗

CVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability · RaqibCTI