GPU VulnDB

Database/Control plane, storage & DevOps

Cisco Secure Firewall Management Center: unauthenticated HTTP request yields root on the appliance

CVSS 10.0CVE-2026-20079Control plane, storage & DevOpsKnown exploitedcurated

Impact

An unauthenticated attacker who can reach the FMC web interface gets root on the underlying operating system, which means full control of the box that writes policy to every managed firewall in the fleet. In a GPU datacenter that terminates tenant traffic behind Cisco firewalls, that is the device deciding which tenants can reach the management VLAN, the storage network and the fabric; root on it lets an attacker rewrite those rules and hide the change. CISA has this in KEV and Talos reports ongoing exploitation, so treat any exposed FMC as potentially already compromised rather than merely vulnerable. Recovery is not just patching - credentials, policy state and any certificates held on the appliance have to be assumed exposed.

Who can reach it

Anyone who can send HTTP requests to the FMC web interface. No authentication and no user interaction required, so an FMC reachable from a tenant network or the internet is directly exploitable.

What to do

Apply the fixed release named in the Cisco advisory; the record does not list version numbers, so take them from the advisory itself. An FMC upgrade reboots the appliance, so managed firewalls run on last-pushed policy during the window - no dataplane outage, but no policy changes either. Because this is under active exploitation, restrict the web interface to the management network immediately and hunt for compromise before assuming a patch is sufficient.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.