Critical 10.0 CVSS Flaw in Cisco Secure FMC Hands Hackers Root Access to Enterprise Firewalls
ID: cb84c963-0ae6-574d-a192-47fdca23c365
STIX ID: report--cb84c963-0ae6-574d-a192-47fdca23c365
Feed Name: securityonline.info
**Critical RCE in Cisco Secure FMC (CVE-2026-20131)** — Researchers disclosed a critical CVE-2026-20131 vulnerability (CVSS 10.0) in the web-based management interface of Cisco Secure Firewall Management Center that allows unauthenticated remote code execution via insecure deserialization of a Java byte stream; successful exploitation could grant root access enabling manipulation of security policies and lateral movement. Cisco Security Cloud Control (SCC) is being patched automatically, there are no workarounds, and Cisco PSIRT reports no known exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
