Skip to main content

CVE detail

CVE-2026-20131

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

CVSS 10.0 · CriticalBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
19 evidence mentions in the snapshot
Diversity score
20.0
10 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
1
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
19 source links · newest first
  • " One-click device compromise Hacking Into Samsung's Mobile Devices A set of vulnerabilities affecting Samsung devices (CVE-2025-21079 and CVE-2025-58486) could be chained to result in remote system-level compromise triggered by clicking on a link delivered via an ad or a messaging application. "What distinguishes this entry from previous submissions i

    newsthehackernews.comAug 6, 2026, 3:24 PM
  • Cisco fixed critical and high-severity flawsSecurity Affairs

    Cisco fixed critical flaws that could allow attackers to bypass authentication, run code, and gain access to sensitive data. Cisco released patches for two critical and six high-severity vulnerabilities. These flaws could let attackers bypass authentication, execute malicious code, escalate privileges, and access sensitive information. One of these critical flaws is CVE-2026-20093 (CVSS score of […]

    newssecurityaffairs.comApr 2, 2026, 5:04 PM
  • CVE-2026-20131Horizon3.ai

    CVE-2026-20131 allows unauthenticated remote code execution in Cisco FMC via insecure deserialization. Exploited in ransomware campaigns—patch immediately.

    exploithorizon3.aiMar 31, 2026, 6:05 PM
  • 30th March – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Iranian state-affiliated threat group Handala Hack has breached FBI director’s Patel’s personal Gmail account and leaked many personal photos and documents. This follows the FBI’s seizure of domains related to Handala Hack’s […]

    vendorresearch.checkpoint.comMar 30, 2026, 12:53 PM
  • 23rd March – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 23rd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Navia Benefit Solutions, a United States-based employee benefits administrator, has disclosed a breach affecting more than 2.6 million individuals after unauthorized access and potential data exfiltration occurred between December 22, 2025 and […]

    vendorresearch.checkpoint.comMar 23, 2026, 1:38 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What smart factories keep getting wrong about cybersecurity In this Help Net Security interview, Packsize CSO Troy Rydman breaks down the biggest vulnerabilities in smart factory environments today, from IoT devices and legacy systems to human error. He explains how unmanaged devices, from sensors to robotic components, often go unpatched and become entry points for attackers. Certificate lifespans are shrinking … More →

    newswww.helpnetsecurity.comMar 22, 2026, 9:00 AM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. WorldLeaks ransomware group breached the City of Los Angels PolyShell flaw exposes Magento and Adobe Commerce […]

    newssecurityaffairs.comMar 22, 2026, 12:48 AM
  • A critical vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) that Cisco disclosed and patched in early March 2026 has been exploited as a zero-day by the Interlock ransomware gang, Amazon CISO and VP of Security Engineering CJ Moses revealed. “Our research [using Amazon’s MadPot system of honeypots] found that Interlock was exploiting this vulnerability 36 days before its public disclosure, beginning January 26, 2026,” he said on Wednesday. CVE-2026-20131 exploited as zero-day for … More →

    newswww.helpnetsecurity.comMar 20, 2026, 1:21 PM
  • One of the world’s most active ransomware groups, Interlock, started exploiting a critical-rated Cisco firewall vulnerability as a zero day weeks before it was patched in early March, Amazon has revealed. The vulnerability in question is CVE-2026-20131, a remotely exploitable deserialization flaw in Cisco Secure Firewall Management Center (FMC) Software which was given a maximum […]

    newswww.csoonline.comMar 19, 2026, 6:25 PM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Cisco FMC and Cisco SCC Firewall Management to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management, tracked as CVE-2026-20131 (CVSS score […]

    newssecurityaffairs.comMar 19, 2026, 5:37 PM
  • The Interlock ransomware group has exploited a Cisco FMC zero-day RCE vulnerability in attacks since late January. The Interlock ransomware group has been exploiting a critical zero-day RCE vulnerability, tracked as CVE-2026-20131 (CVSS score of 10.0), in Cisco Secure Firewall Management Center (FMC) since late January. The vulnerability is a remote code execution flaw that […]

    newssecurityaffairs.comMar 19, 2026, 9:22 AM
  • Amazon found evidence that the FMC software vulnerability has been exploited since late January, and found links to Russia.

    newswww.securityweek.comMar 19, 2026, 8:57 AM
  • Cisco has handed security teams one of the largest ever patching workloads affecting its firewall products, including fixes for two ‘perfect 10’ vulnerabilities in the company’s Secure Firewall Management Center (FMC) Software. Overall, the March 4 release, the first of its semiannual firewall updates for 2026, addresses 25 security advisories covering 48 individual CVEs. The […]

    newswww.csoonline.comMar 5, 2026, 5:19 PM
  • Cisco has confirmed that two Catalyst SD-WAN Manager vulnerabilities (CVE-2026-20128 and CVE-2026-20122) patched in late February 2025 are being exploited by attackers. The exploited vulnerabilities (CVE-2026-20128, CVE-2026-20122) CVE-2026-20128 is a bug in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager, which could allow an authenticated, local attacker to gain DCA user privileges on an affected system. “To exploit this vulnerability, the attacker must have valid vmanage credentials on the affected system,” Cisco … More →

    newswww.helpnetsecurity.comMar 5, 2026, 1:53 PM
  • Cisco has rolled out patches for 48 vulnerabilities in Firewall ASA, Secure FMC, and Secure FTD products.

    newswww.securityweek.comMar 5, 2026, 8:50 AM
  • Cisco patched two critical Secure FMC vulnerabilities that could let attackers gain root access to managed firewalls. Cisco addressed two maximum-severity vulnerabilities in its Secure Firewall Management Center (FMC) that could allow attackers to gain root access. Cisco Secure Firewall Management Center (FMC) is a centralized management platform for Cisco firewalls. It lets administrators configure, […]

    newssecurityaffairs.comMar 4, 2026, 10:10 PM
  • No excerpt available.

    Mitigationwww.cisa.govMar 4, 2026, 6:16 PM
  • No excerpt available.

    Vendor Advisoryaws.amazon.comMar 4, 2026, 6:16 PM
  • No excerpt available.

    Vendor Advisorysec.cloudapps.cisco.comMar 4, 2026, 6:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-10571

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user c…

    CVSS 5.7 · Medium
    1 mention
  • CVE-2026-66256

    ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shin…

    CVSS 7.2 · High
    2 mentions
  • CVE-2026-28176

    Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.

    CVSS 8.8 · High
    1 mention
  • CVE-2026-28149

    Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.

    CVSS 9.8 · Critical
    1 mention
  • CVE-2026-27380

    Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.

    CVSS 7.2 · High
    1 mention
  • CVE-2026-67579

    Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resu…

    CVSS 7.5 · High
    4 mentions