CVE-2026-20131

Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
October 08, 2025
Published Date
March 04, 2026
Last Updated
March 25, 2026
Vendor
Cisco
Product
Cisco Secure Firewall Management Center (FMC)
Description
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
Tags
cisa

CVSS Scores

CVSS v3.1

10.0 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 12:10:30 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 12:10:30 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel