A product listed for the second time: arbitrary code as root on a security console
Added on 19 March 2026 with a remediation date of 22 March. The record states that an unauthenticated remote attacker could execute arbitrary Java code as root through the management interface.
Key facts
- CVE IDCVE-2026-20131
- Affected (vendor / product)Cisco Secure Firewall Management Center (FMC)
- CWECWE-502
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2026-03-22 (U.S. federal civilian agencies, BOD 22-01)
Key points
- A deserialization of untrusted data flaw in Cisco Secure Firewall Management Center and related management.
- An unauthenticated remote attacker could execute arbitrary Java code as root through the management interface.
- Added 19 March 2026 with a 22 March deadline, a three-day window, with ransomware use confirmed.
- This is the product second appearance; 107 products appear exactly twice, covering 214 records.
1The tier of exactly two
The five records so far belonged to products listed between 17 and 172 times. This product is on its second appearance. Recounting the 1,695 KEV records this site holds as of 2026-09-06 by product, 107 products appear exactly twice, accounting for 214 records.
2The machine that defends is the target
The console placed there to defend can be driven, without authentication, at the highest privilege. Rewrite the defensive configuration and everything behind it is affected. The record does not say why the window is three days, but it is hard to read that as unrelated to this shape.
3The deserialization family
Deserialization of untrusted data (CWE-502) reconstructs data received from outside directly into objects inside a program. Unintended processing runs during that reconstruction, so sending data is enough to reach code execution. The same family recurs across other products in these records.
The series closes with the 485 products listed only once.
Why it matters
Even for rarely listed products, records combining no authentication, top-level privilege and a short window belong at the front of the queue. Compromise of a security console reaches everything it manages.
FAQ
Are products with fewer appearances safer?
What is a deserialization vulnerability?
Why does a management console matter so much?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).