Vulnerabilities & Exploits · DDoS
Unauthenticated RCE in Secure Firewall Management Center A deserialization flaw in the web interface of Cisco Secure Firewall Management Center (FMC) allows unauthenticated remote attackers to execute arbitrary Java code as root. Exploit requires sending a crafted serialized Java object; internet-facing FMC instances are at highest risk.
5 sources · Mar 5
CVEs in this update
6 CVEs
Across Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software.
0 critical · 0 high · 6 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-20020 · 6.8 MEDIUM
Timeline Sources Mar 5 Help Net Security
Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilities - Help Net Security
Two Cisco Catalyst SD-WAN Manager vulnerabilities (CVE-2026-20128, CVE-2026-20122) patched in late February 2025 are being exploited.
original Mar 5 Infosecurity Magazine
Cisco Issues Patches for 48 Vulnerabilities
Two of the 48 Cisco vulnerabilities, affecting Secure Firewall Management Center, are maximum-severity flaws
original Mar 5 SecurityWeek
Cisco Patches Critical Vulnerabilities in Enterprise Networking Products
Cisco has rolled out patches for 48 vulnerabilities in Firewall ASA, Secure FMC, and Secure FTD products.
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-03-26
Every edition of this story: Unauthenticated RCE in Secure Firewall Management Center
More from today
Vulnerabilities & Exploits · DDoS
Unauthenticated RCE in Secure Firewall Management Center A deserialization flaw in the web interface of Cisco Secure Firewall Management Center (FMC) allows unauthenticated remote attackers to execute arbitrary Java code as root. Exploit requires sending a crafted serialized Java object; internet-facing FMC instances are at highest risk.
5 sources · Mar 5
CVEs in this update
6 CVEs
Across Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software.
0 critical · 0 high · 6 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-20020 · 6.8 MEDIUM
Timeline Sources Mar 5 Help Net Security
Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilities - Help Net Security
Two Cisco Catalyst SD-WAN Manager vulnerabilities (CVE-2026-20128, CVE-2026-20122) patched in late February 2025 are being exploited.
original Mar 5 Infosecurity Magazine
Cisco Issues Patches for 48 Vulnerabilities
Two of the 48 Cisco vulnerabilities, affecting Secure Firewall Management Center, are maximum-severity flaws
original Mar 5 SecurityWeek
Cisco Patches Critical Vulnerabilities in Enterprise Networking Products
Cisco has rolled out patches for 48 vulnerabilities in Firewall ASA, Secure FMC, and Secure FTD products.
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-03-26
Every edition of this story: Unauthenticated RCE in Secure Firewall Management Center
More from today