logo

Cisco fixes maximum-severity Secure FMC bugs threatening firewall security

ID: bf000e10-8fb6-5bad-81bb-b3eb23312345

STIX ID: report--bf000e10-8fb6-5bad-81bb-b3eb23312345

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Cisco patched two maximum-severity vulnerabilities in Secure Firewall Management Center: CVE-2026-20079 (authentication bypass allowing unauthenticated attackers to execute scripts and gain root) and CVE-2026-20131 (unauthenticated Java deserialization remote code execution enabling arbitrary code as root). Both are rated CVSS 10.0, CVE-2026-20131 also impacts Security Cloud Control (SCC) Firewall Management, there are no workarounds, and Cisco PSIRT reports no known public disclosure or active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.