cbcvebase.
CVE-2026-20131
published 2026-03-04

CVE-2026-20131: A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker…

PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2026-03-22
Exploited in the wild
EPSS
27.55%
97.9th percentile
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Affected

142 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center
ciscocisco_secure_firewall_management_center

Detection & IOCsextracted from sources · hover to see the quote

ip37[.]27[.]244[.]222
other6000322: Java serialization Remote Command Execution
other6000042: Java Deserialization using YSoSerial tool detection
  • Detect crafted HTTP requests containing serialized Java objects (ysoserial-generated payloads) sent to Cisco FMC web management endpoints; the PoC iterates over candidate endpoints that accept serialized Java data.
  • Hunt for memory-resident web shells, custom Java- and JavaScript-based RATs, and proxy infrastructure on Cisco FMC hosts as post-exploitation persistence mechanisms used by Interlock.
  • Alert on unexpected execution of ConnectWise ScreenConnect, Volatility, and Certify on Cisco FMC hosts, as Interlock uses these legitimate tools for remote access, credential theft, and privilege escalation post-compromise.
  • Check Point IPS signature 'Cisco Secure Firewall Management Center Insecure Deserialization (CVE-2026-20131)' provides detection coverage for exploitation attempts.
  • Exploitation began as a zero-day on January 26, 2026 — over a month before the March 4, 2026 Cisco patch — so retrospective log review of FMC web management interface traffic from that date forward is warranted.
  • Monitor C2 communications from compromised FMC hosts for HTTP/HTTPS traffic with dynamic key rotation and use of temporary proxy layers, characteristic of Interlock's C2 infrastructure.
  • ·Cisco FMC versions 6.x (all versions) are affected and have no patch available within the 6.x branch; upgrade to a patched release is required.
  • ·If the FMC management interface does not have public internet access, the attack surface is reduced but not eliminated.
  • ·No workaround exists for on-premises Cisco FMC deployments; applying the vendor patch is the only remediation.
  • ·The vulnerability also affects Cisco Security Cloud Control (SCC) Firewall Management (SaaS-based), not only on-premises FMC.
  • ·A public PoC exploit was shared on GitHub by user sak110 (Sadaf Athar Khan) on March 11, 2026, lowering the barrier for exploitation; its accuracy and efficacy have not been independently verified.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.