Skip to content
COOEY

EXPOSURES › CVE-2026-20131

CVE-2026-20131

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-03-19 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-20131 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildsupply-chainunpatched

Cisco FMC and SCC allow unauthenticated remote attackers to execute arbitrary Java code as root via deserialization of untrusted data.

This critical vulnerability enables remote code execution as root without authentication, directly threatening the integrity of Cisco-managed firewalls and cloud control systems. DIB organizations must immediately patch affected FMC and SCC deployments to prevent ransomware or supply-chain attacks that could compromise network security controls. Failure to patch exposes critical infrastructure to exploitation before a fix is available.

Shame score — A critical RCE vulnerability in a widely deployed management interface that allows unauthenticated remote code execution as root.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized