PT-2026-22978 · Cisco · Cisco Secure Firewall Management Center (Fmc)

Brandon Sakai

·

Published

2026-03-04

·

Updated

2026-04-30

·

CVE-2026-20079

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Secure Firewall Management Center (FMC) (affected versions not specified)
Description A flaw in the web interface of Cisco Secure Firewall Management Center (FMC) Software allows an unauthenticated remote attacker to bypass authentication and execute script files to gain root access to the underlying operating system. This issue stems from an improper system process created during boot time. Exploitation occurs by sending crafted HTTP requests to the device. Technical analysis indicates the use of Java Byte-Stream via HTTP POST requests to trigger a deserialization process, where the readObject() method initiates a gadget chain involving LazyMap and InvokerTransformer, ultimately leading to the execution of the exec() command with root privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

BDU:2026-06300
CVE-2026-20079

Affected Products

Cisco Secure Firewall Management Center (Fmc)