logo

Cisco Secure Firewall Vulnerability Exposes Systems to Remote Code Execution by Attackers

ID: e9cf8411-a635-5022-97ef-d3707be9f1a8

STIX ID: report--e9cf8411-a635-5022-97ef-d3707be9f1a8

Feed Name: GBHackers

Threat Score
95/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Divya

...
...

Cisco has released emergency updates for CVE-2026-20131, a critical (CVSS 10.0) insecure Java deserialization vulnerability in Secure Firewall Management Center and SCC Firewall Management that permits unauthenticated remote arbitrary code execution as root; attackers are observed exploiting it in the wild (March 2026), there are no practical workarounds for on-prem FMC deployments, Cisco has deployed hotfixes for its SaaS SCC service, and administrators are urged to apply the fixed releases immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.