Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
- Severity
- Critical10CVSS 3.1, Critical
- Known exploited
- Known exploitedFederal remediation due date: 22 Mar 2026
- Exploit prediction
- 43%
- Published
- 4 Mar 2026Updated 14 Aug 2026 · Last verified 30 Sept 2026
Known remediation
Fixed releases per branch, as the vendor states them. Patcharo never infers a fix.
Cisco Secure Firewall Management Center (FMC)
Vendor advisory- 10.0No fix published
- 7.7No fix published
- 7.6No fix published
- 7.4No fix published
- 7.3No fix published
- 7.2No fix published
- 7.1No fix published
- 7.0No fix published
- 6.4No fix published
Description
Title, description and vendor guidance are quoted from the source records.
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
Weakness: CWE-502
Known exploited
Added to CISA KEV on 19 Mar 2026
Federal remediation due date: 22 Mar 2026
Known use in ransomware campaigns
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploit prediction
43% probability of exploitation in the next 30 days (percentile 99%).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the source states, per branch
Versions matched by Patcharo
Cisco Secure Firewall Management Center (FMC)Source: Cisco (CVE record)
| Branch | Affected | Fixed in |
|---|---|---|
| 10.0 | Exact releases: 10.0 | |
| 7.7 | Exact releases: 7.7, 7.7.10, 7.7.10.1, 7.7.11 | |
| 7.6 | Exact releases: 7.6, 7.6.1, 7.6.2, 7.6.2.1, 7.6.4 | |
| 7.4 | Exact releases: 7.4, 7.4.1, 7.4.1.1, 7.4.2, 7.4.2.1, 7.4.2.2, 7.4.2.3, 7.4.2.4, 7.4.3, 7.4.4, 7.4.5 | |
| 7.3 | Exact releases: 7.3, 7.3.1, 7.3.1.1, 7.3.1.2 | |
| 7.2 | Exact releases: 7.2, 7.2.0.1, 7.2.1, 7.2.2, 7.2.3, 7.2.3.1, 7.2.4, 7.2.4.1, 7.2.5, 7.2.5.1, 7.2.6, 7.2.7, 7.2.5.2, 7.2.8, 7.2.8.1, 7.2.9, 7.2.10, 7.2.10.1, 7.2.10.2 | |
| 7.1 | Exact releases: 7.1, 7.1.0.1, 7.1.0.2, 7.1.0.3 | |
| 7.0 | Exact releases: 7.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.6.1, 7.0.6.2, 7.0.6.3, 7.0.7, 7.0.8, 7.0.8.1 | |
| 6.4 | Exact releases: 6.4.0.13, 6.4.0.14, 6.4.0.15, 6.4.0.16, 6.4.0.17, 6.4.0.18 |
Versions not listed are not assessed (shown as Unknown).
References
- cisco-sa-fmc-rce-NKhnULJh(opens in a new tab)
- https://aws.amazon.com/blogs/security/amazon-threat-intelligence-teams-identify-interlock-ransomware-campaign-targeting-enterprise-firewalls/(opens in a new tab)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20131(opens in a new tab)
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- Cisco (CVE record)
- Cisco (CVE record) · 30 Sept 2026 at 00:17 UTC · Parser patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 30 Sept 2026 at 00:17 UTC · Parser patcharo-kev/1.0.0
- NVD
- NVD · 27 Sept 2026 at 23:44 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 Sept 2026 at 23:46 UTC · Parser patcharo-epss/1.0.0
Last verified: 30 Sept 2026 at 00:17 UTC