CRITICALCISA KEVIN THE WILD

CVE-2026-20131

CWE-502Published: March 4, 2026· Updated: Jun 17, 2026

10.0
CVSS v3.1
EPSS:0.44%probability of exploitation in 30 daysPercentile:62.7th

Official Description

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.

Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

NVD Source

Risk Analysis

A critical vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software allows an unauthenticated, remote attacker to execute arbitrary Java code as root. This is due to insecure deserialization of user-supplied Java byte streams. With a CVSS score of 10.0 and inclusion in CISA's KEV, this is a critical vulnerability.

Active exploitation of this vulnerability has been observed in the wild. The flaw is remotely exploitable with low attack complexity, making it a significant threat.

Recommended Action

Apply the latest security updates from Cisco for Secure Firewall Management Center (FMC) Software. If the FMC management interface does not require public internet access, restrict its network exposure.

Generated by the CTIWATCH analysis pipeline from this CVE's metadata (CVSS, EPSS, KEV status, exploit intelligence). Verify against vendor advisories before acting.

Technical Analysis

CVE-2026-20131 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 10.0.

The vulnerability has a "Changed" scope, meaning successful exploitation can impact components beyond the vulnerable component itself — such as the host operating system or adjacent services.

CISA has added CVE-2026-20131 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. U.S. federal agencies are required to patch this within the mandated timeframe, and all organizations should treat remediation as urgent.

From a weakness classification perspective (CWE-502): Insecure deserialization vulnerabilities allow attackers to inject malicious objects during deserialization, potentially enabling remote code execution.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorNetwork
Attack ComplexityLow
Privileges Req.None
User InteractionNone
ScopeChanged
Impact
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Vendors & Products

Cisco1 product(s)
secure firewall management center
Source: NVD CPE · 71 total CPE entries

Exploit & PoC Resources

ACTIVE EXPLOITATIONConfirmed exploitation in the wild
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

News & Research Mentioning CVE-2026-20131

CISA Orders US Government to Patch Maximum Severity Cisco Flaw
Infosecurity Magazine· Mar 23, 2026

CISA added CVE-2026-20131 to its KEV catalog as it is being used in ransomware campaigns

CISA orders feds to patch max-severity Cisco flaw by Sunday
BleepingComputer· Mar 20, 2026

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity vulnerability, CVE-2026-20131, in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22. [...] [xlite_meta score:58 src:BleepingComputer xlite_fp:972511c439a2e3f33b67a02b7b55a52ebd6284d46a07abdac361add0165e5a69]

CISA Adds One Known Exploited Vulnerability to Catalog
CISA Alerts· Mar 19, 2026

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20131 Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch [xlite_meta score:58 src:CISA Alerts xlite_fp:2ae3e056ec11cddce6bde24e1df29a619b3eb3ab01b91dbd93b17d44476cec75]

Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access
The Hacker News· Mar 18, 2026

Amazon Threat Intelligence is warning of an active Interlock ransomware campaign that's exploiting a recently disclosed critical security flaw in Cisco Secure Firewall Management Center (FMC) Software. The vulnerability in question is CVE-2026-20131 (CVSS score: 10.0), a case of insecure deserialization of user-supplied Java byte stream, which could allow an unauthenticated, remote attacker to [xlite_meta score:65 src:The Hacker News xlite_fp:091fdf6cba59a0cbb14dc2c13b4fd98eba3235e6b427b1cbd26e28500e38a6b6]

All References (3)

Quick Facts

CVE IDCVE-2026-20131
CVSS Score10.0 / 10
SeverityCRITICAL
WeaknessCWE-502
CISA KEVYES — Active Exploitation
ExploitIN THE WILD
EPSS (30d)0.44%
Affected1 vendor(s)
PublishedMar 4, 2026

Known Threat Actors

Interlock
financial
wa
financial
vect
financial
B0
financial
interlock
financial
core
financial

Organizations Hit via This CVE123

+111 more organizations

Related CVEs (CWE-502)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-20131 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
  • !CISA KEV: Federal agencies must patch per BOD 22-01 timeline
  • !Active exploitation confirmed — treat as P1
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.