CVE-2026-20079
Cisco Secure Firewall Management Center authentication bypass - a hardcoded internal session id is accepted from the network, giving an unauthenticated attacker the authenticated console and script execution as root (CVSS 10.0, CISA KEV)
- Severity
- critical
- Affected product
- Cisco Secure Firewall Management Center
- Affected versions
- Cisco Secure Firewall Management Center all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 36% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-09-10
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Cisco Secure Firewall Management Center appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-10. The day's highest-value CVE: 10.0, on KEV the day it published, EPSS 0.36, and Talos reporting ongoing exploitation of unpatched instances. NOT version-gated and it does not need to be - the version is not anonymously readable (see the appliances.json row) and the bug is DIRECTLY OBSERVABLE instead, which is a stronger claim than any version match: FMC's internal csm_processes worker talks to its own web tier over CGISESSID, and that session id is honoured on requests arriving from the network. The `bypass` block below is the proof, taken from the public nuclei template for this CVE, and both of its arms are required - see appliance_tools._confirm_bypass. The request is a read-only GET of the About page, so confirming it reads a model/OS/hostname banner and changes nothing; contrast CVE-2026-20349 on the ASA row, which is deliberately never probed because its proof is an outage. Fix: Cisco's per-train hotfixes, with a consolidated hardening release the week of 2026-09-14.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →