CVE-2026-20131
published 2026-03-04CVE-2026-20131: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker…
PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2026-03-22
Exploited in the wild
EPSS
27.55%
97.9th percentile
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
Affected
142 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted HTTP requests containing serialized Java objects (ysoserial-generated payloads) sent to Cisco FMC web management endpoints; the PoC iterates over candidate endpoints that accept serialized Java data. ↗
- →Hunt for memory-resident web shells, custom Java- and JavaScript-based RATs, and proxy infrastructure on Cisco FMC hosts as post-exploitation persistence mechanisms used by Interlock. ↗
- →Alert on unexpected execution of ConnectWise ScreenConnect, Volatility, and Certify on Cisco FMC hosts, as Interlock uses these legitimate tools for remote access, credential theft, and privilege escalation post-compromise. ↗
- →Check Point IPS signature 'Cisco Secure Firewall Management Center Insecure Deserialization (CVE-2026-20131)' provides detection coverage for exploitation attempts. ↗
- →Exploitation began as a zero-day on January 26, 2026 — over a month before the March 4, 2026 Cisco patch — so retrospective log review of FMC web management interface traffic from that date forward is warranted. ↗
- →Monitor C2 communications from compromised FMC hosts for HTTP/HTTPS traffic with dynamic key rotation and use of temporary proxy layers, characteristic of Interlock's C2 infrastructure. ↗
- ·Cisco FMC versions 6.x (all versions) are affected and have no patch available within the 6.x branch; upgrade to a patched release is required. ↗
- ·If the FMC management interface does not have public internet access, the attack surface is reduced but not eliminated. ↗
- ·No workaround exists for on-premises Cisco FMC deployments; applying the vendor patch is the only remediation. ↗
- ·The vulnerability also affects Cisco Security Cloud Control (SCC) Firewall Management (SaaS-based), not only on-premises FMC. ↗
- ·A public PoC exploit was shared on GitHub by user sak110 (Sadaf Athar Khan) on March 11, 2026, lowering the barrier for exploitation; its accuracy and efficacy have not been independently verified. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r229-mj76-g2qx: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote
ghsa_unreviewed·2026-03-04
CVE-2026-20131 [CRITICAL] CWE-502 GHSA-r229-mj76-g2qx: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
VulnCheck
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
vulncheck·2026·CVSS 10.0
CVE-2026-20131 [CRITICAL] CWE-502 Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
Affected: Cisco Secure Firewall Management Center (FMC)
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https:/
CISA
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
cisa·2026-03-19·CVSS 10.0
CVE-2026-20131 [CRITICAL] CWE-502 Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
Vulnerability: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
Affected: Cisco Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://sec.cloudapps.cisco.com/security/center/c
Cisco
Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
vendor_cisco·2026-03-05·CVSS 10.0
CVE-2026-20131 [CRITICAL] CWE-502 Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerab
Cisco
Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20131 Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
CVE-2026-20131: Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root . Note: If the FMC management interface does not have public internet access, the attack surface that is associated wit
No detection rules found.
No public exploits indexed.
Securelist
IT threat evolution in Q1 2026. Non-mobile statistics
blogs_securelist·2026-05-18
CVE-2026-20131 IT threat evolution in Q1 2026. Non-mobile statistics
AMR
Table of Contents
Quarterly figures
Ransomware
Quarterly trends and highlights
Law enforcement success
Vulnerabilities and attacks
The most prolific groups
Number of new variants
Number of users attacked by ransomware Trojans
Attack geography
TOP 10 countries and territories attacked by ransomware Trojans
TOP 10 most common families of ransomware Trojans
Miners
Number of new variants
Number of users attacked by miners
Attack geography
TOP 10 countries and territories attacked by miners
Attacks on macOS
TOP 20 threats to macOS
Geography of threats to macOS
TOP 10 countries and territories by share of attacked users
IoT threat statistics
TOP 10 threats delivered to IoT devices
Attacks on IoT honeypots
Attacks via web resources
TOP 10 countries and territories th
Bleepingcomputer
Cisco says critical Webex Services flaw requires customer action
blogs_bleepingcomputer·2026-04-16·CVSS 9.9
[CRITICAL] Cisco says critical Webex Services flaw requires customer action
## Cisco says critical Webex Services flaw requires customer action
## Sergiu Gatlan
Cisco has released security updates to patch four critical vulnerabilities, including a fixed improper certificate validation flaw in the company's cloud-based Webex Services platform that requires further customer action.
Webex Services is a customer experience platform that unifies communication across hybrid work environments, enabling team members to call, meet, and message each other from any location or device.
Tracked as CVE-2026-20184 , the Webex vulnerability was found in the single sign-on (SSO) integration with Control Hub (a web-based portal that helps IT admins manage Webex settings) and allows remote attackers with no privileges to impersonate any user.
"Prior to this vulnerability being
Recorded Future
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day
blogs_recorded_future·2026-04-13·CVSS 9.8
[CRITICAL] March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day
## March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day
In March 2026, Insikt Group® identified 31 high-impact vulnerabilities that should be prioritized for remediation , 29 of which had a Very Critical Recorded Future Risk Score.
These vulnerabilities affected products from the following vendors: Cisco, Microsoft, Google, ConnectWise, Langflow, Citrix, Aquasecurity, Nginx UI, Qualcomm, F5, Craft CMS, Laravel, Apple, Synacor, Wing FTP Server, n8n, Omnissa, SolarWinds, Ivanti, Hikvision, Rockwell, and Broadcom. This month’s most affected vendors were Microsoft and Apple, together accounting for approximately 32% of the 31 vulnerabilities.
One vulnerability ( CVE-2017-7921 affecting Hikvision) is approximately nine ye
Bleepingcomputer
Critical Cisco IMC auth bypass gives attackers Admin access
blogs_bleepingcomputer·2026-04-02·CVSS 9.8
[CRITICAL] Critical Cisco IMC auth bypass gives attackers Admin access
## Critical Cisco IMC auth bypass gives attackers Admin access
## Sergiu Gatlan
Cisco has released security updates to address several critical and high-severity vulnerabilities, including an Integrated Management Controller (IMC) authentication bypass that allows attackers to gain Admin access.
Also known as CIMC, Cisco IMC is a hardware module embedded on the motherboard of Cisco servers that provides out-of-band management (even if the operating system is powered off or crashed) for UCS C-Series and E-Series servers via multiple interfaces, including XML API, web (WebUI), and command-line (CLI).
Tracked as CVE-2026-20093 , the vulnerability was found in the Cisco IMC password change functionality and can be remotely exploited by unauthenticated attackers to bypass authentication and
Checkpoint
30th March – Threat Intelligence Report
blogs_checkpoint·2026-03-30
CVE-2026-20131 30th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 30th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Iranian state-affiliated threat group Handala Hack has breached FBI director’s Patel’s personal Gmail account and leaked many personal photos and documents. This follows the FBI’s seizure of domains related to Handala Hack’s activity last week, due to the group’s sustained targeting of Israeli and American entities, which incr
Hackernews
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
blogs_hackernews·2026-03-23
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories.
This edition covers a mix of issues: supply chain attacks hitting CI/CD setups, long-abused IoT devices being shut down, and exploits moving quickly from disclosure to real attacks. There are also new malware tricks showing attackers are becoming more patient and creative.
It’s a mix of old problems that never go away and new methods that are harder to detect. Th
Zscaler
CVE-2026-20131: Analysis of FMC RCE | ThreatLabz
blogs_zscaler·2026-03-23·CVSS 10.0
[CRITICAL] CVE-2026-20131: Analysis of FMC RCE | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Checkpoint
23rd March – Threat Intelligence Report
blogs_checkpoint·2026-03-23
CVE-2026-33017 23rd March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 23rd March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 23rd March, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Navia Benefit Solutions, a United States-based employee benefits administrator, has disclosed a breach affecting more than 2.6 million individuals after unauthorized access and potential data exfiltration occurred between December 22, 2025 and January 15, 2026. Exposed information may include personal, health, and benefits dat
Bleepingcomputer
CISA orders feds to patch max-severity Cisco flaw by Sunday
blogs_bleepingcomputer·2026-03-20·CVSS 10.0
CVE-2026-20131 [CRITICAL] CISA orders feds to patch max-severity Cisco flaw by Sunday
## CISA orders feds to patch max-severity Cisco flaw by Sunday
## Bill Toulas
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity vulnerability, CVE-2026-20131, in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22.
Cisco published a security bulletin about the flaw on March 4, urging system administrators to apply the security updates as soon as possible and warning that no workarounds are available.
The Cisco Secure Firewall Management Center (FMC) is a centralized administration system for critical Cisco network security appliances, such as firewalls, application control, intrusion prevention, URL filtering, and malware protection.
“A vulnerability in the web-based management interface of Cisco Secure F
Bleepingcomputer
Ransomware gang exploits Cisco flaw in zero-day attacks since January
blogs_bleepingcomputer·2026-03-18·CVSS 10.0
[CRITICAL] Ransomware gang exploits Cisco flaw in zero-day attacks since January
## Ransomware gang exploits Cisco flaw in zero-day attacks since January
## Sergiu Gatlan
The Interlock ransomware gang has been exploiting a maximum severity remote code execution (RCE) vulnerability in Cisco's Secure Firewall Management Center (FMC) software in zero-day attacks since late January.
The Interlock ransomware operation surfaced in September 2024 and has been linked to ClickFix and to malware attacks in which they deployed a remote access trojan called NodeSnake on the networks of multiple U.K. universities.
Interlock has also claimed responsibility for attacks on DaVita , Kettering Health , the Texas Tech University System , and the city of Saint Paul , Minnesota. More recently, IBM X-Force researchers reported that Interlock operators have deployed a new malware strain
Bleepingcomputer
Cisco flags more SD-WAN flaws as actively exploited in attacks
blogs_bleepingcomputer·2026-03-05·CVSS 5.4
[MEDIUM] Cisco flags more SD-WAN flaws as actively exploited in attacks
## Cisco flags more SD-WAN flaws as actively exploited in attacks
## Sergiu Gatlan
Cisco has flagged two Catalyst SD-WAN Manager security flaws as actively exploited in the wild, urging administrators to upgrade vulnerable devices.
Catalyst SD-WAN Manager (formerly vManage) is network management software that enables admins to monitor and manage up to 6,000 Catalyst SD-WAN devices from a single centralized dashboard.
"In March 2026, the Cisco PSIRT became aware of active exploitation of the vulnerabilities that are described in CVE-2026-20128 and CVE-2026-20122 only," the company warned in an update to a February 25 advisory.
"The vulnerabilities that are described in the other CVEs in this advisory are not known to have been compromised. Cisco strongly recommends that customers upgr
Bleepingcomputer
Cisco warns of max severity Secure FMC flaws giving root access
blogs_bleepingcomputer·2026-03-04·CVSS 10.0
[CRITICAL] Cisco warns of max severity Secure FMC flaws giving root access
## Cisco warns of max severity Secure FMC flaws giving root access
## Sergiu Gatlan
Cisco has released security updates to patch two maximum-severity vulnerabilities in its Secure Firewall Management Center (FMC) software.
Secure FMC is a web or SSH-based interface for admins to manage Cisco firewalls and configure application control, intrusion prevention, URL filtering, and advanced malware protection.
Both vulnerabilities can be exploited remotely by unauthenticated attackers: the authentication bypass flaw ( CVE-2026-20079 ) allows attackers to gain root access to the underlying operating system, while the remote code execution (RCE) vulnerability ( CVE-2026-20131 ) lets them execute arbitrary Java code as root on unpatched devices.
"An attacker could exploit this vulnerability by
Greynoiseio
NoiseLetter March 2026
blogs_greynoiseio
NoiseLetter March 2026
Events, events… and yes, even more events. 🌍 GreyNoise has been on the move. March kept us busy with stops at eCrimes in London and SecIT in Hanover—but we’re just getting started. Over the next few months, we’ll be hitting the road for CrowdStrike CrowdTours across eight cities, heading to Glasgow to speak and sponsor CyberUK, and making our way to Tampa for H-ISAC. If you’ll be at any of these (or nearby), we’d love to connect.
And while we’ve been racking up miles, we haven’t slowed down on the research front. We’ve just released some exciting new findings—with even more coming in the next few weeks—so keep an eye out.
Thanks, as always, for being part of the GreyNoise community.
Featured
About this new report
Every enterprise firewall processes traffic from residential IP space. T
Wiz
CVE-2026-20131 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-20131 [CRITICAL] CVE-2026-20131 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20131 :
Cisco Secure Firewall Management Center vulnerability analysis and mitigation
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJhhttps://aws.amazon.com/blogs/security/amazon-threat-intelligence-teams-identify-interlock-ransomware-campaign-targeting-enterprise-firewalls/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20131
2026-03-04
Published
2026-03-19
Added to CISA KEV
Exploited in the wild