Cisco Secure Firewall Management Flaw Allows Remote Code Execution
ID: 2a525704-946a-5c93-8251-b341af78cf81
STIX ID: report--2a525704-946a-5c93-8251-b341af78cf81
Feed Name: GBHackers
Cisco disclosed a critical CVE-2026-20131 vulnerability (CVSS 10.0) in Secure Firewall Management Centre caused by insecure deserialization of Java objects that allows unauthenticated remote attackers to execute code as root. The flaw affects on-premises FMC and SCC management systems (SCC SaaS is auto-updated), has no temporary workaround, and requires immediate application of the March 2026 vendor patches to mitigate the high risk, although Cisco reports no evidence of exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
