logo

Cisco reveals 2 max-severity defects in firewall management software

ID: 05903dd0-176e-52d9-805b-b3cacace3fa1

STIX ID: report--05903dd0-176e-52d9-805b-b3cacace3fa1

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2026-03-05

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

**Executive summary:** Cisco disclosed two critical vulnerabilities in Cisco Secure Firewall Management Center (CVE-2026-20079 and CVE-2026-20131) that allow unauthenticated attackers to bypass authentication and execute arbitrary code — including elevation to root — via a boot-time process weakness and a Java deserialization flaw; Cisco released patches and reported no known exploitation but advised immediate upgrades as there are no workarounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.