Vulnerabilities & Exploits · DDoS

Unauthenticated RCE in Secure Firewall Management Center

A deserialization flaw in the web interface of Cisco Secure Firewall Management Center (FMC) allows unauthenticated remote attackers to execute arbitrary Java code as root. Exploit requires sending a crafted serialized Java object; internet-facing FMC instances are at highest risk.

5 sources · Mar 5

CVEs in this update

6 CVEs

Across Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software.

0 critical · 0 high · 6 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-20020 · 6.8 MEDIUM

Timeline

Sources

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-03-26

Every edition of this story: Unauthenticated RCE in Secure Firewall Management Center

More from today