← Back to news

Cisco fixes maximum-severity Secure FMC bugs threatening firewall security

Security Affairs04/03/2026, 22:10
Read full article →

Summary

AI-Generated

Key Points:

  • Two critical vulnerabilities (CVE-2026-20079 and CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) allow unauthenticated remote attackers to gain root access.
  • The vulnerabilities impact the web interface of Cisco FMC, enabling attackers to bypass authentication and execute arbitrary code, posing significant risks to network security.
  • Immediate patching is recommended as there are no workarounds available for these vulnerabilities.

Technical Details: CVE-2026-20079 allows attackers to bypass authentication via crafted HTTP requests, while CVE-2026-20131 exploits insecure Java deserialization to execute arbitrary code. Both vulnerabilities have a CVSS score of 10.0, indicating maximum severity.

MITRE ATT&CK Techniques:

  • T1078 - Valid Accounts (Defense Evasion)
  • T1203 - Exploitation for Client Execution (Execution)

IOCs Mentioned: None mentioned.

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.