CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. It is an authentication bypass using an alternate path or channel that can enable unauthenticated remote attackers to execute script files and obtain root access to the underlying operating system.
The flaw allows an attacker to bypass authentication remotely without valid credentials. Successful exploitation can lead to script execution and full administrative control of an affected device. The National Vulnerability Database rates CVE-2026-20079 at CVSS 10.0, Critical. The available data does not confirm whether a patch is available; its patch status is listed as unknown.
CISA’s KEV listing confirms that attackers are actively exploiting the vulnerability. The available information does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 12 September 2026.
CISA requires organisations to apply mitigations in accordance with Cisco’s instructions, comply with its BOD 26-04 guidance on prioritising security updates based on risk, and follow the applicable Forensics Triage Requirements. For cloud services, agencies must follow the relevant BOD 26-04 guidance or discontinue use if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and follow BOD 26-04 patching requirements. FCEB agencies are directly affected, but all organisations should review their exposure to Cisco FMC and SCC Firewall Management.
See the NVD entry and CISA KEV catalogue for full details.