Two critical, unauthenticated remote code execution vulnerabilities in the Cisco Secure Firewall Management Center carry CVSS scores of 10.0. Both allow attackers to gain root access to the system that configures and manages the enterprise security perimeter — the management plane that firewalls depend on to enforce policy.
CVE-2026-20131 is an insecure deserialization flaw in the FMC web-based management interface. It requires no authentication, no user interaction, and has low attack complexity. An attacker sends a crafted serialized Java object to the web interface and executes arbitrary code as root. Cisco’s Keane O’Kelley of the Advanced Security Initiatives Group found it during internal testing. The advisory went live March 4, 2026.
The Interlock ransomware group got there first. Amazon’s MadPot global sensor network detected exploitation beginning January 26, 2026 — 51 days before the public disclosure and 36 days before Cisco became aware of the issue. Interlock runs a double-extortion model without affiliates. The group deployed a multi-stage toolkit including custom Remote Access Trojans and reconnaissance scripts. A misconfigured infrastructure server exposed the group’s operational toolkit to Amazon’s researchers. CISA added CVE-2026-20131 to its Known Exploited Vulnerabilities catalog on March 19, 2026.
CVE-2026-20079 is an authentication bypass caused by an improperly configured system process created at boot time. Also CVSS 10.0, also unauthenticated, also remote. Brandon Sakai of Cisco found it. Disclosed the same day — March 4, 2026 — but active exploitation came later. Cisco PSIRT observed it in the wild in August 2026. Cisco Talos tracks the activity as UAT-12197 and a second cluster. The observed toolkit includes web shells, Java/JAR-based command executors, Netcat reverse shells, and a variant of the Cyclops Blink malware implant. CISA added it to the KEV catalog on September 9, 2026.
The detection method for CVE-2026-20079 is specific: run zgrep "package_info.*license" /var/log/messages* in expert mode on the FMC. If the output includes /var/tmp/license.tmp, the device may have been compromised. Cisco TAC should be contacted immediately. The advisory was updated September 16, 2026, replacing earlier hot fixes with security hardening releases.
The architectural problem is the CVSS scope. CVE-2026-20131 carries a “Changed” scope rating — meaning exploitation of the FMC does not stay contained to the management interface. It extends to the managed Firepower Threat Defense devices. The FMC is the central point of control for the entire managed firewall estate. Compromise the controller, and the reach extends across the security infrastructure it administers.
This is not isolated. The Cisco Nexus 9000 Silicon One RCE (CVE-2026-20212, CVSS 9.8) and the Cisco NX-OS bundle — CVE-2026-76471, CVE-2026-76465, and two others — follow the same pattern: unauthenticated critical RCE in enterprise infrastructure components. Four unauthenticated root RCE advisories across four planes of one OS in a single disclosure cycle. The management plane of security infrastructure is becoming the primary attack surface.
Fixed releases for both FMC CVEs: 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2, and 10.1.0. No workarounds exist for either vulnerability. Previously provided hot fixes have been replaced by the security hardening releases. Cisco recommends upgrading immediately. Snort rules 66082 and 66083 provide detection coverage for CVE-2026-20131; rules 66075 through 66080 cover CVE-2026-20079. Both advisories are part of the March 2026 Semiannual Cisco Secure Firewall Advisory Bundled Publication. If the FMC management interface is not exposed to the public internet, the attack surface is reduced — but not eliminated.
