logo

Cisco Secure Firewall Management Flaw Allows Remote Code Execution

ID: 2a525704-946a-5c93-8251-b341af78cf81

STIX ID: report--2a525704-946a-5c93-8251-b341af78cf81

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Divya

...
...

Cisco disclosed a critical CVE-2026-20131 vulnerability (CVSS 10.0) in Secure Firewall Management Centre caused by insecure deserialization of Java objects that allows unauthenticated remote attackers to execute code as root. The flaw affects on-premises FMC and SCC management systems (SCC SaaS is auto-updated), has no temporary workaround, and requires immediate application of the March 2026 vendor patches to mitigate the high risk, although Cisco reports no evidence of exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.