> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# CVE-2026-20079 — Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- URL: https://f4n6.co.uk/security-feed/cve-2026-20079-cisco-secure-firewall-management-center-fmc-and-security-cloud-control-scc-firewall-management-cisco-firewall-management-center-authentication-bypass-using-an-alternate-p/
- Published: 2026-09-09T21:27:56.000Z
- Updated: 2026-09-09T21:27:56.000Z
- Author: Jeff Davies
- Tags: #security-feed, CVE-2026-20079

---

## 1\. Executive summary

CVE-2026-20079 is a CVSS 10.0 CRITICAL authentication bypass using an alternate path or channel (CWE-288) affecting Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. An unauthenticated, remote attacker can bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system — full compromise of the management plane that centrally controls an organisation's entire Cisco firewall estate. The vulnerability is **not** currently listed in CISA's Known Exploited Vulnerabilities catalogue; EPSS stands at 36%, indicating a substantial probability of exploitation in the wild. FMC is a high-value target for EMEA financial services: compromise of the management plane enables an attacker to read or rewrite security policy across every managed firewall, effectively neutralising the network perimeter. Note that a related FMC flaw, CVE-2026-20316 (hard-coded password), is confirmed as actively exploited per CISA KEV — see §3 — which raises the realistic likelihood that FMC estates are already under active reconnaissance.

## 2\. Regulatory framing

| Article                                                                     | Trigger (the fact in this item)                                                                                                                                                                                                                                                            | Practical impact                                                                                                                                                               |
| --------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| DORA Art. 24: digital operational resilience testing — general requirements | The affected product is the central management plane for the entity's firewall estate; a CVSS 10.0 unauthenticated remote root condition in that plane is a finding that must feed the entity's resilience-testing programme (TLPT/threat-led testing scoping and remediation validation). | Re-scope vulnerability scanning and TLPT to include FMC/SCC management interfaces; verify patch deployment as a testable control, not just a ticket.                           |
| DORA Art. 28: ICT third-party risk — general principles                     | Where firewall management is delivered via Cisco Security Cloud Control (SCC), a SaaS management plane, the vulnerability sits with a critical ICT third-party service provider and its patching status is a live third-party risk.                                                        | Obtain written confirmation from Cisco/SCC of remediation status and dates; record the exposure in the third-party register and escalate through contract-management channels. |

No NIS2 or UK NIS article is cited here: the generic fact that a patch is available does not, on its own, engage NIS2 Art. 21(2)(d) or Art. 23 beyond what applies to any vulnerability, and no incident has been confirmed at a client.

## 3\. Technical analysis & attack chain

**Vulnerability mechanism (confirmed from NVD/vendor advisory):** Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication bypass using an alternate path or channel (CWE-288). The flaw allows an **unauthenticated, remote attacker** to bypass authentication and **execute script files on an affected device, obtaining root access to the underlying operating system**. No credentials, no user interaction, and no privileged network position are required as a precondition. The CVSS 10.0 score reflects this worst-case combination: network vector, no attack-complexity barrier, no privileges, no user interaction, and full impact on confidentiality, integrity and availability.

### Attack chain (confirmed steps only)

1. **Reconnaissance:** Attacker identifies an internet-reachable or internally reachable FMC web management interface or SCC Firewall Management instance.
2. **Initial access:** Attacker reaches the affected management service and exploits the alternate-path/channel authentication bypass — no valid credentials required.
3. **Execution:** The bypass permits execution of script files on the affected device.
4. **Privilege escalation / full compromise:** Script execution yields **root on the underlying operating system** of the FMC/SCC appliance.
5. **Post-compromise impact (inherent to the platform, not observed):** With root on the management center, an attacker can read and modify security policy, device configurations and credentials for every firewall the FMC manages, and pivot toward managed devices. This step is an assessment of platform capability, not an observed campaign behaviour.

**What the source does NOT give us:** The NVD entry and vendor text do not specify the affected FMC/SCC software versions, the exact alternate path or channel abused, the protocol/port of the vulnerable interface, or a fixed software release. Do not rely on assumptions here — pull the Cisco advisory for version matrices before scoping patching.

**Related context — treat as a single, corroborated cluster:** A second, distinct FMC vulnerability, **CVE-2026-20316** (use of hard-coded password, low-privileged account in the FMC web interface, reported by Jimi Sebree of Horizon3.ai), is **confirmed actively exploited** — it is listed in CISA KEV (remediation due 2026-08-01) and Cisco/ANSSI/CISA warnings describe zero-day exploitation (BleepingComputer, Help Net Security, CERT-FR). This is a different CWE and a different flaw from CVE-2026-20079, but it establishes that FMC web interfaces are an active, in-the-wild target as of July–August 2026\. Any FMC estate that has not been patched and forensically reviewed since CVE-2026-20316 should be treated as potentially compromised before CVE-2026-20079 remediation is even considered. No attribution for the CVE-2026-20316 exploitation is given in any source, and no actor is named — treat any attribution claim as unconfirmed.

**Exploitation status of CVE-2026-20079:** Not in CISA KEV; EPSS 36%. No ransomware campaign use is recorded. No public proof-of-concept or exploit is described in the provided material.

## 4\. Mitigation & containment

### P1 — within 24 hours

1. **Enumerate the estate.** Identify every FMC deployment (physical and virtual) and every SCC Firewall Management tenant. Record software versions against the vendor's affected-version matrix from the Cisco advisory (the NVD entry does not carry the version list — obtain it directly from Cisco).
2. **Remove management-plane exposure.** FMC/SCC management interfaces must not be internet-facing. Enforce management access via an isolated management VLAN/management plane, restrict the FMC web UI (typically HTTPS/443) to named administration source ranges at the network layer, and remove any NAT/public DNS entries exposing it. CISA's required action for this CVE explicitly directs stakeholders to evaluate each asset's internet exposure.
3. **Hunt for prior compromise.** Because root-level script execution leaves no reliable application-layer audit trail, review FMC host-level logs, authentication logs for anomalous logins, and out-of-band changes to firewall policies/devices managed by the FMC. Cross-reference with the CVE-2026-20316 exploitation window (active as of July 2026; KEV due date 2026-08-01) — if the estate was unpatched across that window, run a full forensic triage per CISA's "Forensics Triage Requirements" before trusting the platform.

### P2 — within 72 hours

1. **Patch.** Apply the Cisco-provided fixed software release for CVE-2026-20079 to all FMC instances, per vendor instructions. CISA's BOD 26-04 framing applies to US federal agencies, but the risk-based prioritisation logic (CVSS 10.0, unauthenticated remote root, management-plane exposure) makes this a same-week patch for any EMEA financial institution regardless of jurisdiction.
2. **Patch the sibling CVE.** Confirm the estate is also remediated for CVE-2026-20316 (KEV-listed, actively exploited, due 2026-08-01). Any FMC still carrying CVE-2026-20316 after that date is a reportable-grade control failure, not a backlog item.
3. **Rotate credentials.** Rotate all credentials stored in or used by the FMC — device management credentials, admin accounts, and any integrated AD/LDAP bindings — on the assumption that a rooted FMC exposes its credential store.

### P3 — within 7 days

1. **Verify SCC posture.** For SCC (cloud) Firewall Management, obtain Cisco's confirmation of platform remediation and review tenant-side administration controls; CISA's guidance for cloud services applies — if mitigations are unavailable, discontinue use of the affected capability until fixed.
2. **Harden and monitor.** Restrict FMC admin roles, enable (and forward) all FMC authentication and configuration-change logging to the SIEM, and alert on management-interface authentication failures, new admin sessions from unusual sources, and policy changes outside change windows.
3. **Update resilience testing scope.** Fold FMC/SCC into vulnerability scanning and threat-led testing scope (see §2, DORA Art. 24).

## 5\. Indicators of compromise

No indicators of compromise available in the source material for CVE-2026-20079.

No behavioural indicators specific to this vulnerability are described in the sources. The generic post-exploitation behaviours implied by the flaw (unauthenticated script execution yielding root on the FMC host) are covered by the hunting actions in §4 rather than by distinct observables.

## 6\. Detection

Insufficient indicators to author detection rules.

The sources provide no exploit artefacts, no malicious strings, no file paths, no command-line patterns and no network signatures for CVE-2026-20079\. Until Cisco or CISA publish technical detection guidance, monitor for the platform-level behaviours in §4 (management-interface authentication anomalies, unexpected configuration changes on managed firewalls) rather than signature-based detection.

## CVE assessment

1 referenced CVE — 1 critical (CVSS ≥ 9.0)

| CVE                                                                              | CVSS          | Exploited | EPSS | Summary                                                                                                                         |
| -------------------------------------------------------------------------------- | ------------- | --------- | ---- | ------------------------------------------------------------------------------------------------------------------------------- |
| [CVE-2026-20079](https://nvd.nist.gov/vuln/detail/CVE-2026-20079?ref=f4n6.co.uk) | 10.0 Critical | —         | 36%  | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,… |

## 7\. Sources

- NVD — CVE-2026-20079 — Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management: Authentication Bypass Using an Alternate Path or Channel Vulnerability — https://nvd.nist.gov/vuln/detail/CVE-2026-20079 — 2026-09-08
- CISA KEV / NVD — CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC): Use of Hard-coded Password Vulnerability — https://nvd.nist.gov/vuln/detail/CVE-2026-20316 — KEV due date 2026-08-01
- ANSSI CERT-FR — Vulnérabilité dans Cisco Firewall Management Center (CERTFR-2026-AVI-0950) — https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0950/ — 2026-07-30
- BleepingComputer — Cisco warns of FMC static credential flaw exploited in zero-day attacks — https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/ — July 2026
- Help Net Security — Cisco FMC static credentials exploited by attackers (CVE-2026-20316) — https://www.helpnetsecurity.com/2026/07/30/cisco-fmc-cve-2026-20316-exploited/ — 2026-07-30

## 8\. Adverse Trace position

CVE-2026-20079 is a maximum-severity (CVSS 10.0, CRITICAL) unauthenticated remote authentication bypass leading to root on Cisco's central firewall management plane; it is not yet KEV-listed but carries a 36% EPSS score and sits in a product line already under confirmed active exploitation via the sibling CVE-2026-20316 flaw. For EMEA financial services clients running FMC or SCC, this is a perimeter-integrity issue, not a routine patch: root on the management center means an adversary can read and rewrite the security policy of every managed firewall, so exposure should be treated as equivalent to compromise of the network control plane. The absence of published version matrices, exploit details and IOCs in the current material is itself a risk — clients should patch on the vendor advisory rather than wait for exploit confirmation, and any estate that was unpatched during the July–August 2026 CVE-2026-20316 exploitation window should undergo forensic triage before being considered clean. Attribution for the CVE-2026-20316 activity is unconfirmed and no actor is named in any source. Adverse Trace will monitor for KEV listing, EPSS movement, Cisco version/fix details and any published IOCs, and will reissue this advisory at version 2.0 if exploitation of CVE-2026-20079 is confirmed.

---

[Read the original source →](https://nvd.nist.gov/vuln/detail/CVE-2026-20079?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*