CVE-2026-20131 is a critical insecure deserialization vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. Rated with a CVSS score of 10.0, it allows an unauthenticated, remote attacker to execute arbitrary Java code as root, leading to full system compromise. This vulnerability is actively exploited in the wild, notably by the Interlock ransomware group as a zero-day, prompting CISA to issue an emergency directive for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.4.0.13CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.4.0.13:*:*:*:*:*:*:* | ||
6.4.0.14CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.4.0.14:*:*:*:*:*:*:* | ||
6.4.0.15CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.4.0.15:*:*:*:*:*:*:* | ||
6.4.0.16CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.4.0.16:*:*:*:*:*:*:* | ||
6.4.0.17CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.4.0.17:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco Secure Firewall Management Center Insecure Deserialization (CVE-2026-20131)
Mar 26, 2026Cisco Secure Firewall Management Center Insecure Deserialization (CVE-2026-20131)
Mar 26, 2026Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
Mar 4, 2026Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
Mar 4, 2026