60
60
ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability
ZDI discloses CVE-2026-20316, a 9.8-rated unauthenticated authentication bypass in Cisco Secure Firewall Management Center login.cgi.
ZDI-26-533 describes an authentication bypass vulnerability in Cisco Secure Firewall Management Center's login.cgi that allows remote attackers to bypass authentication without any credentials. ZDI assigned a CVSS score of 9.8, and the flaw is tracked as CVE-2026-20316. As a central management plane for firewall infrastructure, compromise could enable broad policy changes.
60
60
60
55
60
60
60
60
47
60
60
60
55
30
30
60
55
60
60
55
60
60
60
42
60
60
60
60
60
57
60
60
60
60
60
60
60
60