Cisco Addresses Critical ‘CVSS 10’ Vulnerabilities in Secure FMC
Mar 5, 2026 // 13:47 - Lina Schonbein


Cisco released a bundled publication of 25 security advisories addressing 48 vulnerabilities across its enterprise networking and firewall products. The patches focus on critical flaws in management and security appliances that could allow attackers to gain full administrative control.

Critical Vulnerabilities (CVSS 10.0)

Two of the most severe flaws affect the Cisco Secure Firewall Management Center (FMC) software:

  • CVE-2026-20079 (Authentication Bypass): An improper system process created at boot time allows unauthenticated remote attackers to send crafted HTTP requests to the web interface. A successful exploit grants root access to the underlying operating system.
  • CVE-2026-20131 (Remote Code Execution): This flaw is caused by the insecure deserialization of user-supplied Java byte streams. Attackers can send a crafted serialized Java object to the web-based management interface to execute arbitrary code with root privileges.

Active Exploitation of SD-WAN Products

Cisco and CISA have warned of ongoing active exploitation of critical flaws in Cisco Catalyst SD-WAN systems:

  • CVE-2026-20127 (CVSS 10.0): An authentication bypass flaw in SD-WAN Controllers and Managers that has been exploited by a sophisticated threat actor (tracked as UAT-8616) since 2023.
  • Active Campaigns: Attackers are using this vulnerability to add “rogue peers” to networks and maintain persistence.

Affected Products and Recommendations

The vulnerabilities impact several major enterprise product lines:

  • Firewalls: Secure Firewall ASA, Secure FMC, and Secure FTD software.
  • SD-WAN: Catalyst SD-WAN Manager and Controller.
  • Collaboration: Unified Communications Manager (Unified CM).

Cisco states there are no workarounds for these critical flaws. Administrators are urged to consult the Cisco Security Advisories and apply the latest software updates immediately.

#(fmc)  #‘cvss  #10’  #addresses  #cisco  #critical  #news  #secure  #vulnerabilities   —   News