LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20131: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 19, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 22, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20131 to its Known Exploited Vulnerabilities catalog on Mar 19, 2026, with a federal patch deadline of Mar 22, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management…

This vulnerability affects Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. It is a deserialization of untrusted data issue in the web-based management interface that permits an unauthenticated remote attacker to run arbitrary Java code with root privileges on the device.

The issue is significant because it enables complete takeover of the management system and is known to be used in ransomware campaigns.

How it works

The weakness is categorized as CWE-502, deserialization of untrusted data. An attacker supplies crafted serialized content to the web-based management interface. When the application deserializes that content without sufficient validation, it can result in execution of attacker-controlled Java code running as root.

Am I affected? How to find it in your systems

Inventory all deployments of Cisco Secure Firewall Management Center (FMC) and Cisco Security Cloud Control (SCC) Firewall Management. Focus on instances that expose the web-based management interface to any network, including internal segments or cloud access paths. Confirm the exact software versions and configurations in use against the vendor advisory, as the vulnerability is tied to specific builds of these products.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation. After patching, review and harden the management interface configuration according to the same advisory.

If you can't patch immediately

Follow the mitigations specified in the vendor instructions. For cloud-managed instances, apply any applicable BOD 22-01 guidance. If mitigations cannot be implemented, discontinue use of the affected product until it can be updated or replaced.

If your data may have been exposed

Because this vulnerability has been used in ransomware activity, organizations should assume that successful exploitation could lead to data access or further compromise. Run a free exposure scan of organizational email addresses against known breach datasets to identify any related account exposure.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Secure Firewall Management Center (FMC)
WeaknessCWE-502
Added to CISA KEVMar 19, 2026
Federal patch deadlineMar 22, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities