Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Release Date: 19th of March 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

Communication and Digital Transformation (DCDT through CERT Vanuatu (CERTVU), provides the following advisory

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-20131 is a critical remote code execution (RCE) vulnerability (CVSS 10.0) affecting Cisco firewall management systems. The flaw is caused by insecure deserialization of untrusted data (CWE-502) in the web-based management interface.

Specifically, the application improperly processes user-supplied Java serialized objects, allowing attackers to inject malicious payloads that execute during deserialization.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2026-20131