CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Critical Remote Code Execution Vulnerability in Cisco Secure Firewall Management Center (CVE-2026-20131)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6259

As cited

Copy frozen at (site build).

vulnerabilities

Critical Remote Code Execution Vulnerability in Cisco Secure Firewall Management Center (CVE-2026-20131)

Cisco disclosed CVE-2026-20131, a critical remote code execution vulnerability in Cisco Secure Firewall Management Center caused by insecure deserialization, with a CVSS score of 10.0. Active exploitation began March 6, 2026, targeting technology sector organizations in the United States, prompting CISA to add it to its Known Exploited Vulnerabilities catalog on March 19, 2026, and mandate federal agency remediation by March 22, 2026. Affected versions span 6.x through 7.4.x, and successful exploitation grants unauthenticated attackers root access to alter firewall rules, disable alerts, and pivot deeper into managed networks.

Why it matters: Organizations managing Cisco FMC instances must patch immediately: unauthenticated attackers are actively exploiting this vulnerability to compromise the central firewall management hub and gain network-wide access; federal agencies face a March 22, 2026 remediation deadline.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Critical Remote Code Execution Vulnerability in Cisco Secure Firewall Management Center (CVE-2026-20131)

Cisco disclosed CVE-2026-20131, a critical remote code execution vulnerability in Cisco Secure Firewall Management Center caused by insecure deserialization, with a CVSS score of 10.0. Active exploitation began March 6, 2026, targeting technology sector organizations in the United States, prompting CISA to add it to its Known Exploited Vulnerabilities catalog on March 19, 2026, and mandate federal agency remediation by March 22, 2026. Affected versions span 6.x through 7.4.x, and successful exploitation grants unauthenticated attackers root access to alter firewall rules, disable alerts, and pivot deeper into managed networks.

Why it matters: Organizations managing Cisco FMC instances must patch immediately: unauthenticated attackers are actively exploiting this vulnerability to compromise the central firewall management hub and gain network-wide access; federal agencies face a March 22, 2026 remediation deadline.

VendorsCiscoOracleGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary