From Advisory to Root: Reproducing CVE-2026-20079 on Cisco Secure FMC
How I reproduced the public Cisco Secure FMC authentication-bypass chain, confirmed root execution, and reviewed the impact on one environment.
WRITE-UPS / RESEARCH
Notes from security testing and tool development, including the failed paths and evidence that shaped the result.
How I reproduced the public Cisco Secure FMC authentication-bypass chain, confirmed root execution, and reviewed the impact on one environment.
Why several familiar Active Directory tools could reach an LDAPS relay but could not reuse it—and how a small ldap3 client solved the application-layer mismatch.
A chronological field guide to diagnosing WebClient NTLM relay to LDAP, writing RBCD, completing S4U, validating access, and cleaning up.
SSH patterns for opening remote Nessus and RDP services, proxying a browser through Kali, and forwarding one service through a jump host.