logo

CVE-2026-20131: Analysis of FMC RCE

ID: 801c57b2-624e-565b-843f-a2d3f0821254

STIX ID: report--801c57b2-624e-565b-843f-a2d3f0821254

Feed Name: Zscaler Security Research Blog

Threat Score
95/100

Date Published: 2026-03-24

Date Updated: 2026-05-01

...
...

Cisco disclosed a critical CVE-2026-20131 RCE in Secure Firewall Management Center (CVSS 10) that stems from insecure Java deserialization and allows unauthenticated attackers to execute arbitrary Java code and gain root. Evidence of active exploitation was observed beginning March 6, 2026, with attackers using publicly available PoC serialized Java payloads against major U.S. technology and software organizations; CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.