logo

CISA Warns of Cisco Secure Firewall Management Center 0-Day Exploited in Ransomware Attacks

ID: f8f5f2af-6757-51b1-aad5-c09b92b138e5

STIX ID: report--f8f5f2af-6757-51b1-aad5-c09b92b138e5

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-20

Date Updated: 2026-04-21

Author: Abinaya

...
...

CISA has warned of a critical zero-day (CVE-2026-20131) in Cisco Secure Firewall Management Center and Cisco Security Cloud Control—an unauthenticated deserialization flaw (CWE-502) in the web management interface that permits remote execution of arbitrary Java code as root. The vulnerability is confirmed to be actively exploited in ransomware campaigns, has been added to the CISA Known Exploited Vulnerabilities Catalog with a federal remediation deadline, and organizations are urged to apply vendor mitigations, restrict access to management interfaces, or take affected systems offline until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.