{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-20079",
  "revision": 1,
  "title": "Cisco Firewall Management Center — Unauthenticated Bypass to Root",
  "summary": "The web interface of Cisco Secure Firewall Management Center lets an unauthenticated remote attacker skip login with crafted web requests, run scripts on the appliance and gain root on the underlying system. Exploited in the wild.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 10,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.75752,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2026-09-09",
    "prerequisites": "Network access to the appliance's web management interface; no credentials needed"
  },
  "mitre_attack": [
    "T1190",
    "T1059"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply Cisco's advisory mitigations to Firewall Management Center now; restrict web interface access to trusted networks and triage exposed appliances for compromise.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-20079",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-20079",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-20079",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "title",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-20079",
      "retrieved_at": "2026-09-20T11:09:51.520Z",
      "confidence": "high",
      "extractor": "human"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20079",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2"
    },
    {
      "type": "exploit",
      "url": "http://seclists.org/fulldisclosure/2026/Aug/80"
    },
    {
      "type": "exploit",
      "url": "https://blog.talosintelligence.com/fmc-ongoing-exploitation/"
    }
  ],
  "published_at": "2026-03-04T18:16:24.230Z",
  "issued_at": "2026-09-20T10:52:56.734Z",
  "tags": [
    "cisco",
    "firewall-management-center",
    "authentication-bypass",
    "network-appliance",
    "web-interface"
  ]
}
