← Vulnerability feed

Vulnerability record · CVE-2026-20131 · published 4 March 2026

CVE-2026-20131: Cisco Secure Firewall Management Center Java deserialization RCE

Cisco · Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC) web management interface deserializes a user-supplied Java byte stream without validation, allowing unauthenticated remote code execution. Because the flaw reaches root on the management appliance, it exposes the control plane for managed firewalls rather than a single endpoint.

10.0 CVSS 3.1 Critical CISA KEV since 19 Mar 2026 Known ransomware use EPSS 43% · top 1.3% CWE-502 · Deserialization of untrusted data
10.0CVSS 3.1 base score
43%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable root RCE with a CVSS score of 10, KEV listing, known ransomware campaign use, and a near-top EPSS percentile.

What it is

Cisco Secure Firewall Management Center (FMC) web management interface deserializes a user-supplied Java byte stream without validation, allowing unauthenticated remote code execution. Because the flaw reaches root on the management appliance, it exposes the control plane for managed firewalls rather than a single endpoint.

Impact

An unauthenticated attacker can execute arbitrary Java code as root on the FMC appliance, gaining full control of the device and the firewalls it manages.

Attack surface

Reachable over the network through the FMC web-based management interface via a crafted serialized Java object; no authentication or user interaction is required per the CVSS vector. Cisco notes the attack surface is reduced if the management interface is not exposed to the public internet.

Exploitation

CISA added this to KEV on 2026-03-19 with a 2026-03-22 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.334 (98.3rd percentile), and a referenced AWS threat intelligence blog describes an Interlock ransomware campaign targeting enterprise firewalls.

What to do

  • Apply the Cisco vendor advisory fix for FMC (and SCC Firewall Management where applicable) immediately, ahead of the KEV due date.
  • If patching cannot be completed, restrict FMC management interface access to trusted internal networks and remove any public internet exposure.
  • Follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
  • Audit FMC management access paths and firewall rules for any internet-facing management listeners.
  • Monitor for and investigate signs of compromise on FMC appliances given documented ransomware campaign use.

Detection

  • Review FMC web management interface logs for anomalous or malformed HTTP POST requests carrying serialized Java payloads.
  • Hunt for unexpected child processes, Java process spawning, or root-level command execution on FMC appliances.
  • Correlate FMC management interface access logs with outbound connections or new listener activity from the appliance.
  • Check for indicators tied to the Interlock ransomware campaign referenced in the AWS threat intelligence report.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-20131 to the Known Exploited Vulnerabilities catalog on 19 March 2026 as "Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 22 March 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20131 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-20079Cisco Secure Firewall Management Center authentication bypass to rootCisco Secure Firewall Management Center (FMC) Software contains an authentication bypass caused by an improper system process created at boot time. A…KEVEPSS 88%analysed5.3CVE-2026-20316Cisco Secure Firewall Management Center static credentials allow unauthenticated loginCisco Secure Firewall Management Center (FMC) Software contains hard-coded credentials for a low-privileged account in its web interface. An unauthen…KEVEPSS 35%analysed10.0CVE-2025-20265Cisco secure firewall management center injection vulnerabilityA vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remo…EPSS 16%9.9CVE-2024-20424Cisco secure firewall management center os command injection vulnerabilityA vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center…EPSS 0.94%9.9CVE-2023-20048Cisco secure firewall management center improper privilege management vulnerabilityA vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to ex…EPSS 16%9.8CVE-2019-16028Cisco secure firewall management center improper authentication vulnerabilityA vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to b…EPSS 3.4%9.8CVE-2020-3318Cisco secure firewall management center hard-coded credentials vulnerabilityMultiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to acces…EPSS 0.96%8.8CVE-2024-20360Cisco secure firewall management center sql injection vulnerabilityA vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attack…EPSS 0.83%

Source: NIST National Vulnerability Database (record CVE-2026-20131), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.