Cisco Secure Firewall Management Center Authentication Bypass Leading to Root Remote Code Execution (CVE-2026-20079)

Release Date: 9th September 2026 (Added 10 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate an on-premises Cisco Secure Firewall Management Center (FMC) appliance. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-20079 is a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), the centralized management platform used to configure, monitor, and administer Cisco Secure Firewall (Firepower) devices across an organization's network. Cisco is one of the world's most widely-deployed networking and security vendors, and FMC is a standard component of any Cisco Firepower-based firewall deployment. Cisco disclosed this vulnerability on 4 March 2026 via Cisco Security Advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2. Cisco disclosed a second, technically distinct maximum-severity vulnerability in the same product on the same day, CVE-2026-20131 (insecure deserialization of a user-supplied Java byte stream, also enabling unauthenticated root remote code execution).

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-20079
  2. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2