Skip to main content

Critical Vulnerability in Cisco Secure Firewall Management Center Under Exploitation

Cisco reports exploitation of CVE-2026-20079 which could allow a remote attacker to bypass authentication

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Cisco reports exploitation of CVE-2026-20079 which could allow a remote attacker to bypass authentication


Threat details

Exploitation of CVE-2026-20079

Cisco has stated that it is aware of active exploitation of CVE-2026-20079 in the wild.

The NHS England National CSOC assesses further exploitation as likely.


Introduction

Cisco has reported active exploitation of a critical vulnerability in Cisco Secure Firewall ASA Software, Cisco Secure Firewall Threat Defense Software, and Cisco Secure Firewall Management Center software. Successful exploitation could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

  • CVE-2026-20079 – Authentication Bypass Using an Alternate Path or Channel vulnerability – CVSS v3.1 score 10.0

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

Cisco has published a Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 advisory following a comprehensive internal security review.

To streamline disclosure, Cisco grouped vulnerabilities according to their underlying Common Weakness Enumeration (CWE) category and assigned a single CVE identifier to each group. The vulnerability discussed in this Cyber Alert, CVE-2026-20079, is grouped under identifier CVE-2026-20329.


Remediation advice

Affected organisations are encouraged to review the Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability advisory and apply the relevant updates as soon as possible.

Additionally, software hardening releases can be found here: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026.



Last edited: 17 September 2026 2:55 pm