← Back to CVE List
Vulnerability Intelligence Report
Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability

CVE-2026-20131

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

CISA KEV SSVC: Active Exploitation Automatable Deserialization
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:31.23%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-502 ↗Deserialization of Untrusted Data

Affected Products & Versions

Vendor Product Affected Versions
Cisco Cisco Secure Firewall Management Center (FMC) 7.0.0 (affected), 7.0.0.1 (affected), 7.0.1 (affected), 7.1.0 (affected), 6.4.0.13 (affected), 7.0.1.1 (affected), 6.4.0.14 (affected), 7.1.0.1 (affected), 7.0.2 (affected), 6.4.0.15 (affected), 7.2.0 (affected), 7.0.2.1 (affected), 7.0.3 (affected), 7.1.0.2 (affected), 7.2.0.1 (affected), 7.0.4 (affected), 7.2.1 (affected), 7.0.5 (affected), 6.4.0.16 (affected), 7.3.0 (affected), 7.2.2 (affected), 7.3.1 (affected), 7.2.3 (affected), 7.1.0.3 (affected), 7.2.3.1 (affected), 7.2.4 (affected), 7.0.6 (affected), 7.2.4.1 (affected), 7.2.5 (affected), 7.3.1.1 (affected), 7.4.0 (affected), 6.4.0.17 (affected), 7.0.6.1 (affected), 7.2.5.1 (affected), 7.4.1 (affected), 7.2.6 (affected), 7.4.1.1 (affected), 7.0.6.2 (affected), 6.4.0.18 (affected), 7.2.7 (affected), 7.2.5.2 (affected), 7.3.1.2 (affected), 7.2.8 (affected), 7.6.0 (affected), 7.4.2 (affected), 7.2.8.1 (affected), 7.0.6.3 (affected), 7.4.2.1 (affected), 7.2.9 (affected), 7.0.7 (affected), 7.7.0 (affected), 7.4.2.2 (affected), 7.2.10 (affected), 7.6.1 (affected), 7.4.2.3 (affected), 7.0.8 (affected), 7.6.2 (affected), 7.7.10 (affected), 7.2.10.1 (affected), 7.0.8.1 (affected), 7.6.2.1 (affected), 7.2.10.2 (affected), 7.7.10.1 (affected), 7.4.2.4 (affected), 7.4.3 (affected), 7.7.11 (affected), 7.6.4 (affected), 10.0.0 (affected), 7.4.4 (affected), 7.4.5 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
31.231%
Vulnerability Class
Deserialization

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCisco Systems, Inc. · Hosted Service · USA
Reserved2025-10-08T11:59:15
Published2026-03-04T17:17:56
Last Updated2026-08-14T03:55:24

LINK COPIED TO CLIPBOARD