CISA Warns of Cisco Secure Firewall Management Center 0-Day Exploited in Ransomware Attacks
A critical zero-day vulnerability in Cisco products has been added to the CISA Known Exploited Vulnerabilities Catalog due to active exploitation in ransomware campaigns. Network defenders and security administrators are advised to take immediate action…
A critical zero-day vulnerability in Cisco products has been added to the CISA Known Exploited Vulnerabilities Catalog due to active exploitation in ransomware campaigns. Network defenders and security administrators are advised to take immediate action to mitigate potential risks.
The vulnerability, tracked as CVE-2026-20131 , affects Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. It is identified as a deserialization of untrusted data flaw (CWE-502) within the web-based management interface.
Deserialization vulnerabilities occur when applications process malicious data streams without proper validation. In this case, an unauthenticated, remote attacker can send a specially crafted serialized Java object to the targeted management interface. This can trigger the exploit, allowing the attacker to execute arbitrary Java code with root privileges on the affected device.
Network defenders and security administrators are advised to take immediate action to mitigate potential risks.
Successful exploitation can lead to complete compromise of the firewall management system, manipulation of security policies, and potential deployment of malicious payloads. The confirmed use of CVE-2026-20131 in ransomware attacks is particularly concerning as it targets perimeter security devices and management consoles, enabling attackers to bypass traditional security measures.
Organizations using these Cisco management solutions are at significant risk of operational disruption if the vulnerability remains unpatched. CISA has set a remediation deadline of March 22, 2026, for federal agencies, and strongly urges private organizations to prioritize patching within their vulnerability management frameworks.
System administrators should apply the mitigations outlined in Cisco's official vendor instructions immediately. If patch deployment is delayed, organizations are advised to restrict network access to the web-based management interfaces or temporarily discontinue the use of the affected products until they are secured.
Based on reporting by Cyber Security News.
