Threat Pulse Cyber threat intelligence · Manera Fintech
← back to catalog

CVE-2026-20131

Cisco / Secure Firewall Management Center (FMC)

Ransomware campaign Added 2026-03-19 Due 2026-03-22

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh ; https://nvd.nist.gov/vuln/detail/CVE-2026-20131

Metadata

Added to KEV2026-03-19
Remediation due2026-03-22
Ransomware useKnown
CWEsCWE-502
Ingested2026-04-24 15:03:13

Cross-mesh regulatory overlay LexiWorld · RegulatoryRadar

If you're breached via this CVE, what disclosure laws and cyber regs fire? Asks LexiWorld and RegulatoryRadar via signed mesh.