CVE-2026-20044: Cisco Secure Firewall Management Center Command Injection Vulnerability
A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrictions on remediation modules while in lockdown mode. An attacker could exploit this vulnerability by sending crafted input to the system CLI of the affected device. A successful exploit could allow the attacker to run arbitrary commands or code as root, even when the system is in lockdown mode. To exploit this vulnerability, the attacker must have valid administrative credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20044?
CVE-2026-20044 is considered a high severity vulnerability due to its potential for arbitrary command execution as root.
How do I fix CVE-2026-20044?
To fix CVE-2026-20044, apply the latest patch released by Cisco for the Secure Firewall Management Center.
Who is affected by CVE-2026-20044?
CVE-2026-20044 affects users of Cisco Secure Firewall Management Center Software that have the lockdown mechanism vulnerability.
What types of attacks can exploit CVE-2026-20044?
CVE-2026-20044 can be exploited by authenticated local attackers to execute arbitrary commands on the system.
Is CVE-2026-20044 easy to exploit?
Exploitation of CVE-2026-20044 requires local access and authentication, but if those conditions are met, it could be relatively straightforward.