logo

U.S. CISA adds a flaw in Cisco FMC and Cisco SCC Firewall Management to its Known Exploited Vulnerabilities catalog

ID: 73017f7b-6b7a-5f30-9df0-fe4428e58d11

STIX ID: report--73017f7b-6b7a-5f30-9df0-fe4428e58d11

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-19

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added CVE-2026-20131 (CVSS 10.0), a remote unauthenticated Java deserialization flaw in Cisco Secure FMC and SCC web management interfaces, to its Known Exploited Vulnerabilities catalog after evidence showed the Interlock ransomware group actively exploited the zero-day starting 26 January 2026; Cisco released fixes in early March and CISA ordered federal remediation by March 22, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.