← Global Threat Landscape

CVE-2026-20079

CWE-288

Critical

104.9

RPS

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

Source: NVD

Signals

CVSS
10.0
Critical · v3.1
EPSS
88.18%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Sept 2026
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-288
Published
4 Mar 2026
Last modified 16 Sept 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2026-20079

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 8 Oct 2026, 05:16 UK time

CVE-2026-20079 · RPS 104.9 · DevSecure Intelligence