PT-2026-22984 · Cisco · Cisco Secure Firewall Management Center

Keane Okelley

·

Published

2026-03-04

·

Updated

2026-03-05

·

CVE-2026-20131

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Secure Firewall Management Center (FMC) Software (affected versions not specified)
Description A flaw exists in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software that could allow a remote attacker, without authentication, to execute arbitrary Java code as root on an affected device. This issue stems from insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this by sending a specially crafted serialized Java object to the web-based management interface. Successful exploitation could lead to arbitrary code execution and root privilege escalation. The attack surface is reduced if the FMC management interface lacks public internet access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-20131

Affected Products

Cisco Secure Firewall Management Center