CVE-2026-20131
Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA notes
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh ; https://nvd.nist.gov/vuln/detail/CVE-2026-20131
Description
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| Cisco | Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.1.0 6.4.0.13 7.0.1.1 6.4.0.14 7.1.0.1 7.0.2 6.4.0.15 7.2.0 7.0.2.1 7.0.3 7.1.0.2 7.2.0.1 7.0.4 7.2.1 7.0.5 6.4.0.16 7.3.0 7.2.2 7.3.1 7.2.3 7.1.0.3 7.2.3.1 7.2.4 7.0.6 7.2.4.1 7.2.5 7.3.1.1 7.4.0 6.4.0.17 7.0.6.1 7.2.5.1 7.4.1 7.2.6 7.4.1.1 7.0.6.2 6.4.0.18 7.2.7 7.2.5.2 7.3.1.2 7.2.8 7.6.0 7.4.2 7.2.8.1 7.0.6.3 7.4.2.1 7.2.9 7.0.7 7.7.0 7.4.2.2 7.2.10 7.6.1 7.4.2.3 7.0.8 7.6.2 7.7.10 7.2.10.1 7.0.8.1 7.6.2.1 7.2.10.2 7.7.10.1 7.4.2.4 7.4.3 7.7.11 7.6.4 10.0.0 7.4.4 7.4.5 |
References
1 LinksRecord Details
More from Cisco
Cisco HyperFlex HX Command Injection Vulnerabilities
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
Cisco HyperFlex HX Command Injection Vulnerabilities
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.