Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cisco Secure Firewall Management Center (FMC) has two critical vulnerabilities, each rated CVSS v3.1 10.0. One bypasses authentication; the other can execute code through insecure deserialization. Both are unauthenticated remote attacks that can give an attacker root access. Cisco reports active exploitation of CVE-2026-20079 and attempted exploitation of CVE-2026-20131, so on-premises administrators should check their exact software release and upgrade to a fixed version.

What are the two critical Cisco FMC vulnerabilities?

The flaws affect the web-based management software, not Cisco ASA or Threat Defense firewall software as such. The Cyber Security Agency of Singapore rated both vulnerabilities CVSS v3.1 10.0 out of 10 in its March 6, 2026 alert.

CVE Vulnerability type Attack and potential result Cisco exploitation reporting
CVE-2026-20079 Authentication bypass An unauthenticated remote attacker sends crafted HTTP requests to bypass authentication and run scripts or commands, potentially gaining root access. Cisco PSIRT reported active exploitation in August 2026.
CVE-2026-20131 Insecure deserialization leading to remote code execution An unauthenticated remote attacker sends a crafted serialized Java object to execute arbitrary Java code as root. Cisco PSIRT reported attempted exploitation in March 2026.

The exploitation reports are not equivalent: Cisco says CVE-2026-20079 was actively exploited, while it became aware of attempted exploitation of CVE-2026-20131. See Cisco’s CVE-2026-20079 advisory and CVE-2026-20131 advisory for the technical details and updates.

Does a vulnerability affect my FMC deployment?

Check the product and where it is managed. The issue concerns the FMC management interface, so the presence of a Cisco firewall device alone does not establish that it is vulnerable. The Singapore agency says CVE-2026-20079 affects all on-premises Secure FMC releases; it identifies CVE-2026-20131 as affecting on-premises FMC and Cisco Security Cloud Control Firewall Management.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Cisco Secure Firewall 1210 Compact Security Appliance with Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200 VPN
  • Functionality: Centralized Management
  • Firewall Protection Supported: Enterprise Security
  • Firewall Protection Supported: Threat Protection
  • Firewall Protection Supported: Secure IPsec VPN Connectivity
  • Firewall Protection Supported: TLS Decryption

On-premises FMC

Administrators should verify the exact installed release and platform against Cisco’s current advisory and Cisco Software Checker. Cisco’s September 2026 hardening release lists these first-fixed Secure FMC/FTD releases:

Release train First-fixed release listed for the September hardening release
7.0 and earlier 7.0.10
7.2 7.2.12
7.4 7.4.8
7.6 7.6.6
7.7 7.7.13
10.0 10.0.2
10.1 10.1.0

These are the release figures Cisco lists for its September hardening release, which includes the CVE-2026-20079 fix along with other internally discovered vulnerabilities. Do not assume this table establishes the first-fixed release for CVE-2026-20131: use its current advisory and Software Checker to confirm the relevant train and cumulative exposure.

Rank #2
Cisco Secure Firewall 1210 compact security appliance with ASA software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200 VPN - 8 x RJ-45
  • Functionality: Centralized Management
  • Firewall Protection Supported: Enterprise Security
  • Firewall Protection Supported: Threat Protection
  • Firewall Protection Supported: Secure IPsec VPN Connectivity
  • Firewall Protection Supported: TLS Decryption

Cisco Security Cloud Control

The cloud-managed service is distinct from an on-premises FMC installation. The Singapore agency says Cisco automatically upgraded the relevant Cisco Security Cloud Control component; it required no user action for that cloud-delivered fix. That does not remove the need for organizations running on-premises FMC to check and patch their own deployment.

How should administrators fix the vulnerabilities?

  1. Identify the deployment. Confirm whether the management system is on-premises FMC or the cloud-managed Cisco Security Cloud Control component, and record the exact installed release and platform.
  2. Check Cisco’s current guidance. Look up the installed version in the relevant CVE-2026-20079 advisory, CVE-2026-20131 advisory, and Software Checker.
  3. Upgrade to the appropriate fixed software. Follow Cisco’s version guidance for the exact software train rather than relying only on a general release list.
  4. If compromise is suspected, contact Cisco TAC. Cisco cautions that a hot fix can prevent future exploitation but may not address an existing compromise.

Cisco says there are no workarounds for either vulnerability. Keeping the FMC management interface off the public internet reduces the attack surface, according to Cisco, but that exposure reduction is not a workaround and does not replace upgrading.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Cisco Secure Firewall 1210 Compact Security Appliance with PoE, Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200
  • Functionality: Centralized Management
  • Firewall Protection Supported: Enterprise Security
  • Firewall Protection Supported: Threat Protection
  • Firewall Protection Supported: Secure IPsec VPN Connectivity
  • Firewall Protection Supported: TLS Decryption
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about exploitation?

Cisco first published both advisories on March 4, 2026. Its CVE-2026-20131 advisory says PSIRT became aware of attempted exploitation in March. In an update published September 16, Cisco said PSIRT became aware of active exploitation of CVE-2026-20079 in August 2026. Cisco’s September 16 hardening release, updated September 18, provides the release table above. The different wording matters: attempted exploitation of one flaw should not be described as confirmed active exploitation of both.

Quick Recap

Bestseller No. 1
Cisco Secure Firewall 1210 Compact Security Appliance with Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200 VPN
Cisco Secure Firewall 1210 Compact Security Appliance with Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200 VPN
Functionality: Centralized Management; Firewall Protection Supported: Enterprise Security; Firewall Protection Supported: Threat Protection
$2,813.38
Bestseller No. 2
Cisco Secure Firewall 1210 compact security appliance with ASA software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200 VPN - 8 x RJ-45
Cisco Secure Firewall 1210 compact security appliance with ASA software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200 VPN - 8 x RJ-45
Functionality: Centralized Management; Firewall Protection Supported: Enterprise Security; Firewall Protection Supported: Threat Protection
$3,000.35
Bestseller No. 3
Cisco Secure Firewall 1210 Compact Security Appliance with PoE, Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200
Cisco Secure Firewall 1210 Compact Security Appliance with PoE, Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T - Gigabit Ethernet - 6.50 Gbit/s Firewall Throughput - 200
Functionality: Centralized Management; Firewall Protection Supported: Enterprise Security; Firewall Protection Supported: Threat Protection
$3,371.31
Bestseller No. 4
Cisco Secure Firewall 1220 Compact Security Appliance with Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T, 10GBase-X - 10 Gigabit Ethernet - 15 Gbit/s Firewall Throughpu
Cisco Secure Firewall 1220 Compact Security Appliance with Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T, 10GBase-X - 10 Gigabit Ethernet - 15 Gbit/s Firewall Throughpu
Functionality: Centralized Management; Firewall Protection Supported: Enterprise Security; Firewall Protection Supported: Threat Protection
$4,591.12
Rank #4
Cisco Secure Firewall 1220 Compact Security Appliance with Threat Defense Software - Centralized Management - 8 Port - 10/100/1000Base-T, 10GBase-X - 10 Gigabit Ethernet - 15 Gbit/s Firewall Throughpu
  • Functionality: Centralized Management
  • Firewall Protection Supported: Enterprise Security
  • Firewall Protection Supported: Threat Protection
  • Firewall Protection Supported: Secure IPsec VPN Connectivity
  • Firewall Protection Supported: TLS Decryption

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.