Critical Vulnerability in Cisco Secure Firewall Management Center Under Exploitation
Cisco reports exploitation of CVE-2026-20079 which could allow a remote attacker to bypass authentication
Summary
Cisco reports exploitation of CVE-2026-20079 which could allow a remote attacker to bypass authentication
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-20079
Cisco has stated that it is aware of active exploitation of CVE-2026-20079 in the wild.
The NHS England National CSOC assesses further exploitation as likely.
Introduction
Cisco has reported active exploitation of a critical vulnerability in Cisco Secure Firewall ASA Software, Cisco Secure Firewall Threat Defense Software, and Cisco Secure Firewall Management Center software. Successful exploitation could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
- CVE-2026-20079 – Authentication Bypass Using an Alternate Path or Channel vulnerability – CVSS v3.1 score 10.0
Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026
Cisco has published a Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 advisory following a comprehensive internal security review.
To streamline disclosure, Cisco grouped vulnerabilities according to their underlying Common Weakness Enumeration (CWE) category and assigned a single CVE identifier to each group. The vulnerability discussed in this Cyber Alert, CVE-2026-20079, is grouped under identifier CVE-2026-20329.
Remediation advice
Affected organisations are encouraged to review the Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability advisory and apply the relevant updates as soon as possible.
Additionally, software hardening releases can be found here: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026.
Definitive source of threat updates
Last edited: 17 September 2026 2:55 pm