LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-20131

CVE-2026-20131 - Vulnerability Analysis

CriticalCVSS: 10.0

Last Updated: March 5, 2026

Cisco Secure Firewall Management Center - Remote Code Execution & Privilege Escalation

Published: March 4, 2026Updated: March 5, 2026Remote Exploitable

Overview

Cisco Secure Firewall Management Center contains an insecure deserialization vulnerability caused by processing user-supplied Java byte streams in the web-based management interface, letting unauthenticated remote attackers execute arbitrary Java code as root, exploit requires access to the management interface.

Severity & Score

Severity: Critical
CVSS Score: 10.0
EPSS Score: 65.0%(Probability of exploitation in next 30 days)

Impact

Unauthenticated remote attackers can execute arbitrary code as root, leading to full system compromise.

Mitigation

Update to the latest available version of Cisco Secure Firewall Management Center.

Social Media Activity(2 posts)

AA
AA
@AAKL
Mar 25, 2026

Grab a coffee. Cisco has a long list of advisories today, one is critical, several are high-severity. This was first published on March 4: Critical: CVE-2026-20131: Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh More: https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity Also, Cisco has tagged GeoVision and MediaArea for zero-day reports https://talosintelligence.com/vulnerability_info #Zeroday #Cisco #infosec #vulnerability @cR0w

View original post
LLMs
LLMs
@LLMs
Mar 25, 2026

Ransomware Interlock explota Zero-Day crítico en Cisco FMC (CVE-2026-20131) El equipo de respuesta a incidentes de Cisco (PSIRT) ha emitido un parche de emergencia extraordinario para abordar una ... https://mastodon.social/tags/Seguridad https://seguridadpy.info/2026/03/ransomware-interlock-explota-zero-day-critico-en-cisco-fmc-cve-2026-20131-html/ | https://awakari.com/sub-details.html?id=LLMs | https://awakari.com/pub-msg.html?id=LvCXuiyUZ3MJaLzkPZ3bVwcKxM0&interestId=LLMs

View original post

Details

CVE ID
CVE-2026-20131
Severity
Critical
CVSS Score
10.0
Type
insecure_deserialization
Status
unconfirmed
EPSS
65.0%
Social Posts
2

CWE

  • CWE-502

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS Score

65.0%Probability of exploitation in the next 30 days