Exploited Known exploited (KEV) Ransomware use CVE-2026-20131

A product listed for the second time: arbitrary code as root on a security console

Cisco Secure Firewall Management Center (FMC) Added to KEV Mar 19, 2026 Federal remediation due 2026-03-22

Added on 19 March 2026 with a remediation date of 22 March. The record states that an unauthenticated remote attacker could execute arbitrary Java code as root through the management interface.

Key facts

  • CVE IDCVE-2026-20131
  • Affected (vendor / product)Cisco Secure Firewall Management Center (FMC)
  • CWECWE-502
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2026-03-22 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • A deserialization of untrusted data flaw in Cisco Secure Firewall Management Center and related management.
  • An unauthenticated remote attacker could execute arbitrary Java code as root through the management interface.
  • Added 19 March 2026 with a 22 March deadline, a three-day window, with ransomware use confirmed.
  • This is the product second appearance; 107 products appear exactly twice, covering 214 records.

1The tier of exactly two

The five records so far belonged to products listed between 17 and 172 times. This product is on its second appearance. Recounting the 1,695 KEV records this site holds as of 2026-09-06 by product, 107 products appear exactly twice, accounting for 214 records.

Times this product appears2107 products appear exactly twice
Window on this record3 daysadded 19 March 2026, due 22 March
Ransomware useconfirmed354 of 1,695 records (20.9%) carry it

2The machine that defends is the target

AspectWindows (172 entries)This product (2 entries)
What it isthe base a device or server runs onthe console that manages a firewall
What access yieldsprivileges on that machinecontrol of the defensive configuration itself
Attacker prerequisite herea foothold, then escalationnone; unauthenticated and remote
Privilege obtainedescalated privilegeroot
Window14 days3 days

The console placed there to defend can be driven, without authentication, at the highest privilege. Rewrite the defensive configuration and everything behind it is affected. The record does not say why the window is three days, but it is hard to read that as unrelated to this shape.

3The deserialization family

Deserialization of untrusted data (CWE-502) reconstructs data received from outside directly into objects inside a program. Unintended processing runs during that reconstruction, so sending data is enough to reach code execution. The same family recurs across other products in these records.

The series closes with the 485 products listed only once.

Why it matters

Even for rarely listed products, records combining no authentication, top-level privilege and a short window belong at the front of the queue. Compromise of a security console reaches everything it manages.

FAQ

Are products with fewer appearances safer?
No. The count is a history of observation, not a measure of risk. This is a second appearance combining a three-day window, no authentication and execution as root.
What is a deserialization vulnerability?
A defect in which data received from outside is reconstructed into program objects, running unintended processing along the way. Sending data can be enough to execute code.
Why does a management console matter so much?
Because the defensive configuration itself can be altered, which affects every device under that management.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#KEV#Known exploited#Cisco#Deserialization#Remediation deadline
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.