Cisco Secure Firewall Management Center Authentication Bypass Vulnerability
A critical vulnerability in Cisco's Firewall Management Center allows remote attackers to bypass login screens and gain full administrative control over the system. Cisco has issued software updates to fix the issue.

English Brief
A critical vulnerability in Cisco's Firewall Management Center allows remote attackers to bypass login screens and gain full administrative control over the system. Cisco has issued software updates to fix the issue.
الموجز العربي
ثغرة تجاوز المصادقة في برنامج Cisco Secure Firewall Management Center
توجد ثغرة أمنية حرجة في نظام إدارة جدار الحماية من سيسكو (Cisco FMC) تتيح للمهاجمين عن بُعد تجاوز شاشات تسجيل الدخول والتحكم الكامل في النظام. أصدرت سيسكو تحديثات برمجية لمعالجة هذه الثغرة.
- 1Identify current FMC software version
- 2Check for available updates via the Cisco FMC web interface or Cisco Software Central
- 3Download and install the latest patch provided by Cisco for the respective version
English Advisory
// Intelligence Summary
A critical authentication bypass vulnerability exists in the web interface of Cisco Secure Firewall Management Center (FMC), identified as CVE-2026-20079. Successful exploitation allows an unauthenticated, remote attacker to gain root access to the underlying operating system.
التقرير العربي
// ملخص استخباراتي
توجد ثغرة أمنية حرجة تتعلق بتجاوز المصادقة في واجهة الويب الخاصة بـ Cisco Secure Firewall Management Center (FMC)، والمعروفة بـ CVE-2026-20079. يتيح الاستغلال الناجح لهذه الثغرة لمهاجم غير مصادق عليه وعن بُعد الحصول على وصول بصلاحيات الجذر (root) إلى نظام التشغيل الأساسي.
// Technical Context
The flaw stems from an improper system process initialized during the device boot sequence. By sending specifically crafted HTTP requests to the web interface, an attacker can trigger this process incorrectly, circumventing authentication mechanisms and facilitating arbitrary script execution.
// السياق الفني
تنشأ الثغرة بسبب عملية نظام غير صحيحة يتم إنشاؤها أثناء تسلسل تشغيل الجهاز (boot sequence). من خلال إرسال طلبات HTTP مصممة خصيصًا إلى واجهة الويب، يمكن للمهاجم تشغيل هذه العملية بشكل غير سليم، مما يؤدي إلى تجاوز آليات المصادقة وتسهيل تنفيذ نصوص برمجية تعسفية.
// Exposure Notes
The vulnerability affects the web management interface of the FMC. Exposure is significantly reduced if the management interface is not accessible from the public internet. There are no known workarounds for this issue.
// ملاحظات التعرض
تؤثر الثغرة على واجهة إدارة الويب الخاصة بـ FMC. يتم تقليل مستوى التعرض بشكل كبير إذا كانت واجهة الإدارة غير متاحة من خلال الإنترنت العام. لا توجد حلول بديلة (workarounds) معروفة لهذه المشكلة حاليًا.
// Defensive Priority
Cisco has released official patches to address this vulnerability. Administrators must verify their software versions and apply the recommended security updates immediately. For further details, refer to the advisory at: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
// أولوية الدفاع
أصدرت سيسكو تحديثات برمجية رسمية لمعالجة هذه الثغرة. يجب على مسؤولي النظام التحقق من إصدارات البرامج لديهم وتطبيق التحديثات الأمنية الموصى بها فورًا. لمزيد من التفاصيل، يرجى مراجعة الاستشارة على الرابط: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
Mitigation Checklist
- 1Identify current FMC software version
- 2Check for available updates via the Cisco FMC web interface or Cisco Software Central
- 3Download and install the latest patch provided by Cisco for the respective version
- 4Limit management interface access to trusted internal IP ranges using Access Control Lists (ACLs)
قائمة إجراءات التخفيف
- 1تحقق من إصدار برنامج FMC الحالي
- 2ابحث عن التحديثات المتاحة عبر واجهة إدارة FMC أو موقع Cisco Software Central
- 3قم بتنزيل وتثبيت آخر تصحيح برمجي مقدم من سيسكو للإصدار الخاص بك
- 4قم بتقييد الوصول إلى واجهة الإدارة بحيث تقتصر على نطاقات IP الداخلية الموثوقة باستخدام قوائم التحكم في الوصول (ACLs)
- Source: Cisco Security Advisories
# 1. Identify current FMC software version
show version
# 2. Check for available updates via the Cisco FMC web interface or Cisco Software Central
# 3. Download and install the latest patch provided by Cisco for the respective version
# 4. Limit management interface access to trusted internal IP ranges using Access Control Lists (ACLs)