Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryperimeter-device-exposureidentity-authentication-vulnerabilityinternet-facing-service-vulnerability

Cisco patches max-severity Secure Firewall Management Center flaws enabling unauthenticated root access

Updated 3mo agoFirst seen Mar 4, 202617 sources

Cisco released security updates for two maximum-severity vulnerabilities in Cisco Secure Firewall Management Center (FMC) that can be exploited remotely by unauthenticated attackers via crafted HTTP requests to the web-based management interface. The issues include an authentication bypass (CVE-2026-20079) that can lead to root access on the underlying operating system and a remote code execution flaw (CVE-2026-20131) that allows execution of arbitrary Java code as root on unpatched systems.

The Canadian Centre for Cyber Security highlighted Cisco’s advisories and urged administrators to review Cisco guidance and apply updates, noting impact to Cisco Security Cloud Control (SCC) Firewall Management and Cisco Secure FMC across versions. Cisco stated its PSIRT had no evidence of active exploitation and no public PoC at the time of publication, while also issuing fixes for additional vulnerabilities (including multiple high-severity issues) across Cisco firewall management and firewall platforms.

Share:
Cisco patches max-severity Secure Firewall Management Center flaws enabling unauthenticated root access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Mar 25, 20263mo ago

VulnCheck publishes exploit chain analysis for CVE-2026-20079

On 2026-03-25, VulnCheck published technical analysis showing a working unauthenticated exploit chain for CVE-2026-20079 in Cisco Secure Firewall Management Center that achieved root command execution. The report described abuse of a boot-time csm_processes session, hardcoded machine-user credentials, token extraction, and CGI functionality, while noting the attack requires a recently rebooted or lightly used target.

CVE-2026-20079 - Cisco FMC Authentication Bypass RCE Analysis | Blog | VulnCheck
Mar 18, 20263mo ago

Cisco warns CVE-2026-20131 is being actively exploited

On 2026-03-18, Cisco updated its advisory for CVE-2026-20131 to state that the critical Secure Firewall Management Center flaw was being exploited in the wild. This reversed Cisco’s March 4 position that no public exploitation or proof-of-concept was known.

CVE-2026-20131: Analysis of FMC RCE | ThreatLabz
Mar 4, 20264mo ago

Cisco updates prior SD-WAN guidance to note active exploitation

On 2026-03-04, Cisco also updated earlier guidance for two Catalyst SD-WAN Manager vulnerabilities, originally published on 2026-02-25, to state they were being exploited in the wild. This was reported alongside the March firewall advisory bundle as a separate development in Cisco's broader security updates.

Canadian Centre for Cyber Security issues alert on Cisco advisories

On 2026-03-04, the Canadian Centre for Cyber Security published alert AV26-197 highlighting Cisco's advisories for Security Cloud Control Firewall Management and Secure Firewall Management Center. The notice urged administrators to review Cisco guidance, follow mitigations, and apply updates as available.

Cisco says no active exploitation or public PoC is known

In the March 4, 2026 advisories, Cisco PSIRT stated it was not aware of public disclosure, proof-of-concept code, or in-the-wild exploitation for the two critical FMC vulnerabilities at the time of publication. Cisco also indicated there were no workarounds and urged customers to upgrade to fixed releases.

Cisco discloses and patches two critical Secure FMC vulnerabilities

On 2026-03-04, Cisco disclosed and released fixes for CVE-2026-20079 and CVE-2026-20131, two CVSS 10.0 vulnerabilities in Cisco Secure Firewall Management Center. Cisco said unauthenticated attackers could exploit the flaws remotely to achieve root-level access, and noted CVE-2026-20131 also affects Cisco Security Cloud Control Firewall Management.

Cisco publishes March 2026 firewall security advisory bundle

On 2026-03-04, Cisco published a bundled set of security advisories covering roughly 48 vulnerabilities across Secure Firewall ASA, Secure Firewall Management Center (FMC), and Secure Firewall Threat Defense (FTD). The release included fixes for two critical FMC web interface flaws and numerous additional high- and medium-severity issues.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

79 LINKEDOpen in app
Vulnerabilities
49 linked
Unauthenticated Root RCE in Cisco Secure Firewall Management Center Web InterfaceAuthentication Bypass to Root RCE in Cisco Secure Firewall Management CenterCisco Secure Firewall ASA multiple context mode SCP cross-context file accessAuthentication Bypass in Cisco Catalyst SD-WAN Controller, Manager, and ValidatorAuthenticated SQL injection in Cisco Secure Firewall Management Center (FMC) REST APIAuthenticated SQL injection in Cisco Secure FMC web-based management interfaceAuthenticated SQL injection in Cisco Secure FMC REST APIDoS via OSPF packet parsing in Cisco Secure Firewall ASA/FTDDoS in Snort 3 Detection Engine via crafted VBA decompression dataDoS via OSPF packet parsing memory corruption in Cisco Secure Firewall ASA/FTDDoS via crafted HTTP to Remote Access SSL VPN Lua interpreter in Cisco ASA/FTDDoS via crafted RPC parsing in Snort 3 detection engine (Cisco products)DoS via IKEv2 packet parsing memory leak in Cisco Secure Firewall ASA/FTDDoS via crafted OSPF LSU packets in Cisco Secure Firewall ASA/FTD (heap corruption)DoS via OSPF LSU out-of-bounds write in Cisco Secure Firewall ASA/FTD (OSPF canonicalization debug)DoS via Snort 3 Detection Engine binder module initialization logic (Cisco products)Unauthenticated Remote DoS via memory exhaustion in Cisco ASA/FTD Remote Access SSL VPNDoS in Snort 3 VBA decompression error handling (infinite loop)Cisco Secure Firewall ASA/FTD IKEv2 Memory Exhaustion DoSDoS via heap overflow in Snort 3 VBA decompression (Cisco products)DoS in Cisco Snort 3 Detection Engine via crafted HTTP mDNS header parsingAuthenticated CLI command injection in Cisco Secure FTD (root OS command execution)Cisco Secure Firewall ASA/FTD SAML SSO DoSAuthenticated CLI input validation DoS in Cisco Secure Firewall Threat Defense (FTD)Cisco Secure Firewall ASA and Secure FTD IKEv2 Denial of Service VulnerabilityDoS in Cisco Snort 3 Detection Engine via crafted SSL handshake parsingDoS in Snort 3 Detection Engine via JSTokenizer HTTP JavaScript normalizationAuthenticated CLI command injection in Cisco Secure FTD Software (root OS command execution)Cisco Secure Firewall ASA/FTD Remote Access SSL VPN Memory Exhaustion DoSOSPF update packet processing buffer overflow DoS in Cisco Secure Firewall ASA/FTDCisco Secure Firewall ASA and FTD Remote Access SSL VPN Authenticated Memory Exhaustion DoSOSPF heap corruption DoS in Cisco Secure Firewall ASA/FTDAuthenticated command injection in Cisco FXOS CLI for Cisco Secure Firewall ASA/FTDAuthenticated command injection in Cisco Secure Firewall Management Center (FMC) lockdown remediation modulesDoS in Cisco Snort 3 VBA decompression error handlingXSS in Cisco Secure Firewall ASA/FTD VPN web servicesArbitrary file write as root via path traversal in Cisco Secure Firewall FMC/FTD sftunnel file synchronizationCisco Secure Firewall ASA TCP Flood Denial of Service VulnerabilityLua code injection leading to root RCE in Cisco Secure Firewall ASA/FTD CLI commandsACL bypass in Cisco Secure Firewall ASA/FTD clustering rule replicationSnort deep packet inspection rule bypass in Cisco Secure Firewall Threat Defense (FTD)Cisco Secure Firewall ASA/FTD VPN Web Server Denial of Service VulnerabilityCisco Secure Firewall ASA/FTD IKEv2 IPsec GCM Traffic Denial of ServiceDoS via crafted TLS packet in Snort 3 Detection Engine (Cisco Secure Firewall FTD)DoS via Snort 3 SSL packet inspection memory management logic error in Cisco Secure Firewall FTDDoS in Cisco Secure Firewall FTD SSL Decryption Do Not Decrypt exclusion (TLS 1.2)SSH key-based authentication bypass in Cisco Secure Firewall ASA proprietary SSH stackClient-side request smuggling in Cisco Secure Firewall ASA/FTD VPN web servicesReflected XSS in Cisco Secure Firewall ASA/FTD SAML 2.0 SSO
Affected products
7 linked
AsyncosApache Http ServerClamavSecure Firewall Threat DefenseSecure Firewall Management Center (Fmc)Secure Firewall Adaptive Security ApplianceClamav
Organizations
23 linked
Cisco SystemsJuniper NetworksBlack DuckVulnCheckFenix24SmartertoolsTrend MicroVerizon CommunicationsBeyondtrustCensysGladinetLinkedinZscalerPalo Alto NetworksAction1SolarWindsFortinetIvantiF5Microsoft CorporationFoFaGoogleSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Cisco patches max-severity Secure Firewall Management Center flaws enabling unauthenticated root access | Mallory