CVE-2026-20131 DetailsDescription A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
A remote code execution vulnerability has been identified in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary Java code with root privileges on the affected device. The issue arises from insecure deserialization of user-supplied Java byte streams. Exploitation involves sending a crafted serialized Java object to the management interface. Note that the vulnerability's impact is reduced if the FMC management interface lacks public internet access.
Cisco has released software updates to address this vulnerability. For guidance on upgrading to a fixed software release, Cisco recommends using the Cisco Software Checker tool, which identifies relevant security advisories and the earliest fixed release. Additional resources are available for help with Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software releases.
Show AI summary Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2026 Exploitation: ActiveAutomatable: YesTechnical Impact: Total
References to Advisories, Solutions, and Tools By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
Vulnerability Name Date Added Due Date Required Action Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability Mar 19, 2026 Mar 22, 2026 Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Weakness Enumeration Affected Products Product Versions cisco secure firewall management center 6.4.0.13
6.4.0.14
6.4.0.15
6.4.0.16
6.4.0.17
6.4.0.18
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.0.2.1
7.0.3
7.0.4
7.0.5
7.0.6
7.0.6.1
7.0.6.2
7.0.6.3
7.0.7
7.0.8
7.0.8.1
7.1.0
7.1.0.1
7.1.0.2
7.1.0.3
7.2.0
7.2.0.1
7.2.1
7.2.2
7.2.3
7.2.3.1
7.2.4
7.2.4.1
7.2.5
7.2.5.1
7.2.5.2
7.2.6
7.2.7
7.2.8
7.2.8.1
7.2.9
7.2.10
7.2.10.1
7.2.10.2
7.3.0
7.3.1
7.3.1.1
7.3.1.2
7.4.0
7.4.1
7.4.1.1
7.4.2
7.4.2.1
7.4.2.2
7.4.2.3
7.4.2.4
7.4.3
7.4.4
7.4.5
7.6.0
7.6.1
7.6.2
7.6.2.1
7.6.3
7.6.4
7.7.0
7.7.10
7.7.10.1
7.7.11
10.0.0
Viewing 5 of 71 versions. View all CPE cpe:2.3:a:cisco:secure_firewall_management_center:6.4.0.13:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:6.4.0.14:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:6.4.0.15:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:6.4.0.16:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:6.4.0.17:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:6.4.0.18:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.0.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.1.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.2.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.4:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.5:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.3:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.7:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.8:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.0.8.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0.3:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.0.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.3:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.3.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.4:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.4.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.5:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.5.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.5.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.6:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.7:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.8:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.8.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.9:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.10:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.10.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.2.10.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.3.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.3.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.3.1.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.3.1.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.4.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.4.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.4.1.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.4.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.4.2.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.4.2.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.4.2.3:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.4.2.4:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.4.3:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.4.4:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.4.5:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.6.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.6.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.6.2:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.6.2.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.6.3:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.6.4:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.7.0:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.7.10:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.7.10.1:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:7.7.11:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_firewall_management_center:10.0.0:*:*:*:*:*:*:* Remediation No remediation found in references.
Change History 10 change records found show changes
Date Action Recorded By Jun 17, 2026 CVE Modified CISA-ADP Jun 17, 2026 CVE Modified [email protected] Mar 25, 2026 Modified Analysis [email protected] Mar 25, 2026 CVE Modified [email protected] Mar 23, 2026 Modified Analysis [email protected] Mar 20, 2026 CVE Modified [email protected] Mar 19, 2026 Initial Analysis [email protected] Mar 19, 2026 CVE Modified CISA-ADP Mar 19, 2026 CVE Modified CISA-ADP Mar 4, 2026 New CVE Received [email protected]