cbcvebase.
CVE-2026-20044
published 2026-03-04

CVE-2026-20044: A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform…

PriorityP336medium6CVSS 3.1
AVLACLPRHUINSUCHIHAN
EPSS
0.14%
3.6th percentile
A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrictions on remediation modules while in lockdown mode. An attacker could exploit this vulnerability by sending crafted input to the system CLI of the affected device. A successful exploit could allow the attacker to run arbitrary commands or code as root, even when the system is in lockdown mode. To exploit this vulnerability, the attacker must have valid administrative credentials.

Affected

79 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
vendor_cisco6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.