← Intelligence Center

Cisco Secure Firewall Management Center Software Vulnerabilities Could Allow for Authentication Bypass

PublishedJul 30, 2026
Updated
VendorCisco
SeverityHigh
Known ExploitedYes Known Exploited
Advisory IDINTEL-000004
CVEs
CVE-2026-20079CVE-2026-20316
Products
  • Cisco Secure FMC Software versions prior to 7.0
  • Cisco Secure FMC Software versions prior to 7.2
  • Cisco Secure FMC Software versions prior to 7.4
  • Cisco Secure FMC Software versions prior to 7.6
  • Cisco Secure FMC Software versions prior to 7.7
  • Cisco Secure FMC Software versions prior to 10.0

Executive Summary

MS-ISAC Advisory 2026-075 (issued 7/30/2026): multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software, the most severe of which could allow authentication bypass. CVE-2026-20079 could allow an unauthenticated, remote attacker to execute script files and obtain root access to the underlying operating system; CVE-2026-20316 could allow login using a low-privileged account to access sensitive data. Cisco PSIRT is aware of active exploitation of CVE-2026-20316, and CISA added it to the Known Exploited Vulnerability Catalog.

Municipal Impact

MS-ISAC rates the risk as High for large and medium government entities and Medium for small government entities. Attack surface is reduced if the FMC management interface is not publicly accessible.

SMB Impact

MS-ISAC rates the risk as High for large and medium business entities, Medium for small business entities, and Low for home users.

Recommended Actions

  1. Apply appropriate updates provided by Cisco to vulnerable systems immediately after appropriate testing.
  2. Ensure the FMC management interface does not have public internet access.
  3. Follow CIS Safeguards for vulnerability management, automated vulnerability scanning, and remediation.

Grey Matter Analysis

Analysis pending review.

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter