← All CVEs NewScan detects
criticalKEV

CVE-2026-20079

Cisco Secure Firewall Management Center authentication bypass - a hardcoded internal session id is accepted from the network, giving an unauthenticated attacker the authenticated console and script execution as root (CVSS 10.0, CISA KEV)

Severity
critical
Affected product
Cisco Secure Firewall Management Center
Affected versions
Cisco Secure Firewall Management Center all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
EPSS
36% chance of exploitation in the next 30 days
Added to NewScan
2026-09-10
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Cisco Secure Firewall Management Center appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-10. The day's highest-value CVE: 10.0, on KEV the day it published, EPSS 0.36, and Talos reporting ongoing exploitation of unpatched instances. NOT version-gated and it does not need to be - the version is not anonymously readable (see the appliances.json row) and the bug is DIRECTLY OBSERVABLE instead, which is a stronger claim than any version match: FMC's internal csm_processes worker talks to its own web tier over CGISESSID, and that session id is honoured on requests arriving from the network. The `bypass` block below is the proof, taken from the public nuclei template for this CVE, and both of its arms are required - see appliance_tools._confirm_bypass. The request is a read-only GET of the About page, so confirming it reads a model/OS/hostname banner and changes nothing; contrast CVE-2026-20349 on the ASA row, which is deliberately never probed because its proof is an outage. Fix: Cisco's per-train hotfixes, with a consolidated hardening release the week of 2026-09-14.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →