• News/
  • https://www.bleepingcomputer.com/news/security/cisco-warns-of-max-severity-secure-fmc-flaws-giving-root-access/

Cisco warns of max severity Secure FMC flaws giving root access

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 4, 2026
·
Updated

Cisco has released security updates to patch two maximum-severity vulnerabilities in its Secure Firewall Management Center (FMC) software. Secure FMC is a web or SSH-based interface for admins to manage Cisco firewalls and configure application control, intrusion prevention, URL filtering, and advanced malware protection. Both vulnerabilities can be exploited remotely by unauthenticated attackers: the authentication bypass flaw (CVE-2026-20079) allows attackers to gain root access to the underlying operating system, while the remote code execution (RCE) vulnerability (CVE-2026-20131) lets them execute arbitrary Java code as root on unpatched devices. "An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device," the CVE-2026-20079 advisory reads. "An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root," Cisco added about CVE-2026-20079. While they both affect Cisco Secure FMC Software, CVE-2026-20131 also affects Cisco Security Cloud Control (SCC) Firewall Management, a cloud-based security policy manager that simplifies policy across Cisco firewalls and other devices. At the moment, the company's Pro...

Read full article

Affected Software

2 affected components
Cisco Secure Firewall Management Center=N/A
Cisco Security Cloud Control Firewall Management=N/A

Frequently Asked Questions

1

What vulnerabilities are discussed in the article?

The article discusses two maximum-severity vulnerabilities in Cisco's Secure Firewall Management Center software that allow root access.

2

Who is affected by these security flaws?

Administrators using Cisco Secure Firewall Management Center to manage their firewalls are affected by these vulnerabilities.

3

What is the severity level of the vulnerabilities mentioned?

The vulnerabilities are classified as maximum severity, indicating a high risk of exploitation.

4

What actions should users take in response to these vulnerabilities?

Users should apply the security updates provided by Cisco to patch the identified vulnerabilities.

5

Is there any specific software version mentioned that is affected?

The article does not specify a version, indicating that the vulnerabilities affect Cisco Secure Firewall Management Center regardless of version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203