ZeroHour

CVE-2026-20340

large

Authenticated Root RCE via Insecure Deserialization in Cisco Secure FMC Software

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Cisco Secure Firewall Management Center (FMC) Software contains a flaw (CWE-502) caused by unsecured deserialization of user-controlled data in the web management interface. An attacker who holds valid credentials for an account with at least the read-only Security Analyst role can authenticate and send a crafted HTTP payload, which is saved by the device and can then be executed on the underlying operating system. Successful exploitation yields arbitrary command execution at the root privilege level, giving full control of the FMC appliance and, by extension, the firewall policies it manages. Any organization running Cisco Secure FMC Software is affected, with the practical risk limited to attackers who can reach the management interface and obtain a low-privileged account. As of now, the flaw is not listed in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Upgrade FMC to the fixed release identified in Cisco's security advisory. Restrict access to the FMC web management interface to trusted management networks, audit accounts holding the Security Analyst or higher roles, and review saved/scheduled configurations and system logs for unexpected payloads or command execution as indicators of prior exploitation.

Affected
Cisco Secure Firewall Management Center (Secure FMC) Software
Estimated exposure
largeTens of thousands of FMC deployments, of which a low-teens-thousands subset is internet-exposed — Cisco Secure Firewall has a large enterprise installed base and FMC is its standard central manager, while public internet scans have historically shown tens of thousands of exposed FMC web consoles; most FMC instances are internal-only,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-controlled data. An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP payload. A successful exploit could allow the attacker to save the crafted payload and then execute it on the underlying operating system as root. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Security Analyst (read-only).

Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.