PT-2026-22984 · Cisco · Cisco Secure Firewall Management Center

·

CVE-2026-20131

·

Published

2026-03-04

·

Updated

2026-06-16

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Secure Firewall Management Center (FMC) (affected versions not specified) Cisco Security Cloud Control (SCC) Firewall Management (affected versions not specified)
Description A flaw in the web-based management interface of Cisco Secure Firewall Management Center (FMC) and Cisco Security Cloud Control (SCC) Firewall Management allows an unauthenticated remote attacker to execute arbitrary Java code with root privileges. The issue is caused by insecure deserialization, which occurs when the software fails to properly validate a user-supplied Java byte stream. An attacker can exploit this by sending a specially crafted serialized Java object to the management interface. This issue was exploited as a zero-day by the Interlock ransomware group starting January 26, 2026, approximately 36 days before public disclosure. Following exploitation, attackers deployed ScreenConnect for persistent access and used PowerShell scripts to harvest software inventories, running services, browser credentials, and network connections before exfiltrating data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02531
CVE-2026-20131

Affected Products

Cisco Secure Firewall Management Center