CVE-2026-20316 in Cisco Secure Firewall Management Center
Cisco published a security advisory for a critical vulnerability in Secure Firewall Management Center (FMC) that allows an unauthenticated remote attacker to execute commands with elevated privileges on the affected system.
The flaw, tracked as CVE-2026-20316, resides in FMC's web management interface and affects software versions 7.2 through 7.4. An attacker can exploit the vulnerability by sending a specially crafted HTTP request to the configuration endpoint, without needing valid credentials.
FMC is the centralized platform many organizations use to manage multiple Cisco Secure Firewall (formerly Firepower) devices distributed across their network — compromising the FMC is equivalent to compromising the management of the organization's entire security perimeter.
Cisco rated the vulnerability at maximum severity on its internal scale and has already published patches for all affected versions. Immediate patching is recommended, along with restricting access to the management interface to trusted management networks in the meantime.