Cisco Secure Firewall Management Flaw Allows Remote Code Execution
Cisco has identified a critical security vulnerability in its Secure Firewall Management Center (FMC) software. With a maximum severity score of 10.0, this vulnerability enables unauthenticated, remote attackers to execute arbitrary code with root…
Cisco has identified a critical security vulnerability in its Secure Firewall Management Center (FMC) software. With a maximum severity score of 10.0, this vulnerability enables unauthenticated, remote attackers to execute arbitrary code with root privileges.
The vulnerability, identified as CVE-2026-20131, is categorized as Remote Code Execution with a CVSS score of 10.0. It involves the insecure deserialization of user-supplied Java byte streams in the web-based management interface.
Discovered during internal security testing by the Cisco Advanced Security Initiatives Group (ASIG), the vulnerability poses a risk of complete system compromise if not addressed.
The vulnerability directly affects Cisco Secure FMC Software and Cisco Security Cloud Control (SCC) Firewall Management systems. Public exposure of the web-based management interface significantly increases the attack surface, though systems accessed only via internal networks are less immediately at risk. However, they remain vulnerable from within the corporate perimeter.
Cisco has identified a critical security vulnerability in its Secure Firewall Management Center (FMC) software.
Cisco Security Cloud Control is a SaaS offering; thus, Cisco manages all backend maintenance, and no manual intervention is needed for SCC as it automatically receives security updates. The Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software are not affected by this vulnerability.
Cisco has confirmed no temporary workarounds exist for this vulnerability. Organizations must apply official vendor patches promptly to protect their infrastructure.
Software Update: Upgrade Cisco Secure FMC to the latest patched release immediately. Access Control: Restrict web management interface access to isolated, trusted networks. Cloud Management: No action needed for SaaS-delivered SCC deployments as they are auto-updated.
Cisco addressed this vulnerability in the March 2026 release of the Cisco Secure Firewall Software Security Advisory Bundled Publication. Network security teams are advised to use the official Cisco Software Checker tool to determine their optimal upgrade paths. Deploying the recommended fixed software versions is crucial to prevent exploitation of this deserialization flaw.
Based on reporting by GBHackers.
