CVE Explorer
CVE-2026-20131
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could al
Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Cisco Secure Firewall Management Center (FMC)","vendor":"Cisco","versions":[{"status":"affected","version":"7.0.0"},{"status":"affected","version":"7.0.0.1"},{"status":"affected","version":"7.0.1"},{"status":"affected","version":"7.1.0"},{"status":"affected","version":"6.4.0.13"},{"status":"affected","version":"7.0.1.1"},{"status":"affected","version":"6.4.0.14"},{"status":"affected","version":"7.1.0.1"},{"status":"affected","version":"7.0.2"},{"status":"affected","version":"6.4.0.15"},{"status":"affected","version":"7.2.0"},{"status":"affected","version":…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:16ef36966f0a424bfa69c48fffd5e693410e0e8ed0446da47cf7fd9dd2180497 · sha256:c15ad0b147b41ab8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:16ef36966f0a424bfa69c48fffd5e693410e0e8ed0446da47cf7fd9dd2180497 · sha256:c15ad0b147b41ab8… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-502","description":"Deserialization of Untrusted Data","lang":"en","type":"cwe"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:16ef36966f0a424bfa69c48fffd5e693410e0e8ed0446da47cf7fd9dd2180497 · sha256:c15ad0b147b41ab8… · /containers/cna/problemTypes/0/descriptions/0
Known exploitation assertions
2 source assertions{"cwes":["CWE-502"],"dateAdded":"2026-03-19","dueDate":"2026-03-22","knownRansomwareCampaignUse":"Known","notes":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh ; https://nvd.nist.gov/vuln/detail/CVE-2026-20131","product":"Secure Firewall Management Center (FMC)","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security …
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:7e855536521213480ccac8e9e3cc304fe549288343950bd91b2d1345137deca1 · sha256:16acee8334e59e44… · /vulnerabilities/111Open source location →
{"cwes":["CWE-502"],"dateAdded":"2026-03-19","dueDate":"2026-03-22","knownRansomwareCampaignUse":"Known","notes":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh ; https://nvd.nist.gov/vuln/detail/CVE-2026-20131","product":"Secure Firewall Management Center (FMC)","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security …
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:1c6fe4a1fa4ae1e69bd0e54873b612ced2b049bc50947decdadf843477fa5852 · sha256:635dff916c4092c0… · /vulnerabilities/114Open source location →
Source references
3 source assertions{"tags":["third-party-advisory"],"url":"https://aws.amazon.com/blogs/security/amazon-threat-intelligence-teams-identify-interlock-ransomware-campaign-targeting-enterprise-firewalls/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:16ef36966f0a424bfa69c48fffd5e693410e0e8ed0446da47cf7fd9dd2180497 · sha256:c15ad0b147b41ab8… · /containers/adp/0/references/0
{"name":"cisco-sa-fmc-rce-NKhnULJh","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:16ef36966f0a424bfa69c48fffd5e693410e0e8ed0446da47cf7fd9dd2180497 · sha256:c15ad0b147b41ab8… · /containers/cna/references/0
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20131"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:16ef36966f0a424bfa69c48fffd5e693410e0e8ed0446da47cf7fd9dd2180497 · sha256:c15ad0b147b41ab8… · /containers/adp/0/references/1
Attribution and limitations
- CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.