Vulnerability record · CVE-2026-20131 · published 4 March 2026
CVE-2026-20131: Cisco Secure Firewall Management Center Java deserialization RCE
Cisco · Secure Firewall Management Center
Cisco Secure Firewall Management Center (FMC) web management interface deserializes a user-supplied Java byte stream without validation, allowing unauthenticated remote code execution. Because the flaw reaches root on the management appliance, it exposes the control plane for managed firewalls rather than a single endpoint.
Description
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable root RCE with a CVSS score of 10, KEV listing, known ransomware campaign use, and a near-top EPSS percentile.
What it is
Cisco Secure Firewall Management Center (FMC) web management interface deserializes a user-supplied Java byte stream without validation, allowing unauthenticated remote code execution. Because the flaw reaches root on the management appliance, it exposes the control plane for managed firewalls rather than a single endpoint.
Impact
An unauthenticated attacker can execute arbitrary Java code as root on the FMC appliance, gaining full control of the device and the firewalls it manages.
Attack surface
Reachable over the network through the FMC web-based management interface via a crafted serialized Java object; no authentication or user interaction is required per the CVSS vector. Cisco notes the attack surface is reduced if the management interface is not exposed to the public internet.
Exploitation
CISA added this to KEV on 2026-03-19 with a 2026-03-22 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.334 (98.3rd percentile), and a referenced AWS threat intelligence blog describes an Interlock ransomware campaign targeting enterprise firewalls.
What to do
- Apply the Cisco vendor advisory fix for FMC (and SCC Firewall Management where applicable) immediately, ahead of the KEV due date.
- If patching cannot be completed, restrict FMC management interface access to trusted internal networks and remove any public internet exposure.
- Follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Audit FMC management access paths and firewall rules for any internet-facing management listeners.
- Monitor for and investigate signs of compromise on FMC appliances given documented ransomware campaign use.
Detection
- Review FMC web management interface logs for anomalous or malformed HTTP POST requests carrying serialized Java payloads.
- Hunt for unexpected child processes, Java process spawning, or root-level command execution on FMC appliances.
- Correlate FMC management interface access logs with outbound connections or new listener activity from the appliance.
- Check for indicators tied to the Interlock ransomware campaign referenced in the AWS threat intelligence report.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-20131 to the Known Exploited Vulnerabilities catalog on 19 March 2026 as "Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 22 March 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-20131 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-20131), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.