CRITICAL · CVSS 10 CISA Known Exploited Vulnerability Used in ransomware attacks

CVE-2026-20131

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrust

Cisco Secure Firewall Management Center (FMC)

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

CVSS
10
CRITICAL
EPSS
42.7%
30-day exploitation
Ransomware groups
1
recorded exploiting
Published
4 Mar 2026
CWE-502

Ransomware groups exploiting CVE-2026-20131

Panzer 34 victims tracked

Exploitation is attributed to these groups across their recorded activity. It does not follow that every organisation they listed was reached through CVE-2026-20131 — the source data does not record an entry point per incident.

Exploitation status

CISA Known Exploited Vulnerabilities

Listed by CISA on 19 March 2026. US federal agencies were required to remediate it by 22 March 2026. CISA records this vulnerability as known to be used in ransomware campaigns.

EPSS — exploitation probability

FIRST puts the probability of exploitation activity in the next 30 days at 42.7%, which is higher than 98.7% of all scored vulnerabilities. EPSS is a forecast of activity, not a measure of severity, and it is rescored daily.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Recent listings by these groups

Disclosures from the groups above, newest first.

Frequently asked questions

Is CVE-2026-20131 being exploited by ransomware groups?

Yes. CVE-2026-20131 is recorded as exploited by Panzer. Between them these groups account for 34 victim disclosures in this database. CISA also records this vulnerability as used in ransomware campaigns.

What does CVE-2026-20131 affect?

CVE-2026-20131 affects Cisco Secure Firewall Management Center (FMC). A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

How severe is CVE-2026-20131?

CVE-2026-20131 is rated CRITICAL with a CVSS base score of 10. EPSS puts the probability of exploitation in the next 30 days at 42.7%, higher than 98.7% of all scored vulnerabilities. It is listed in the CISA Known Exploited Vulnerabilities catalog, with a federal remediation deadline of 22 March 2026.

How should organisations respond to CVE-2026-20131?

Apply the vendor patch for Cisco Secure Firewall Management Center (FMC) as the first priority, and treat any internet-facing instance as the most urgent. Because this vulnerability is associated with ransomware activity, also review whether the affected systems were reachable before patching, rather than assuming that patching alone closes the incident.