Cisco Secure Firewall Management Center (FMC) has two critical vulnerabilities, each rated CVSS v3.1 10.0. One bypasses authentication; the other can execute code through insecure deserialization. Both are unauthenticated remote attacks that can give an attacker root access. Cisco reports active exploitation of CVE-2026-20079 and attempted exploitation of CVE-2026-20131, so on-premises administrators should check their exact software release and upgrade to a fixed version.
What are the two critical Cisco FMC vulnerabilities?
The flaws affect the web-based management software, not Cisco ASA or Threat Defense firewall software as such. The Cyber Security Agency of Singapore rated both vulnerabilities CVSS v3.1 10.0 out of 10 in its March 6, 2026 alert.
| CVE | Vulnerability type | Attack and potential result | Cisco exploitation reporting |
|---|---|---|---|
| CVE-2026-20079 | Authentication bypass | An unauthenticated remote attacker sends crafted HTTP requests to bypass authentication and run scripts or commands, potentially gaining root access. | Cisco PSIRT reported active exploitation in August 2026. |
| CVE-2026-20131 | Insecure deserialization leading to remote code execution | An unauthenticated remote attacker sends a crafted serialized Java object to execute arbitrary Java code as root. | Cisco PSIRT reported attempted exploitation in March 2026. |
The exploitation reports are not equivalent: Cisco says CVE-2026-20079 was actively exploited, while it became aware of attempted exploitation of CVE-2026-20131. See Cisco’s CVE-2026-20079 advisory and CVE-2026-20131 advisory for the technical details and updates.
Does a vulnerability affect my FMC deployment?
Check the product and where it is managed. The issue concerns the FMC management interface, so the presence of a Cisco firewall device alone does not establish that it is vulnerable. The Singapore agency says CVE-2026-20079 affects all on-premises Secure FMC releases; it identifies CVE-2026-20131 as affecting on-premises FMC and Cisco Security Cloud Control Firewall Management.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Functionality: Centralized Management
- Firewall Protection Supported: Enterprise Security
- Firewall Protection Supported: Threat Protection
- Firewall Protection Supported: Secure IPsec VPN Connectivity
- Firewall Protection Supported: TLS Decryption
On-premises FMC
Administrators should verify the exact installed release and platform against Cisco’s current advisory and Cisco Software Checker. Cisco’s September 2026 hardening release lists these first-fixed Secure FMC/FTD releases:
| Release train | First-fixed release listed for the September hardening release |
|---|---|
| 7.0 and earlier | 7.0.10 |
| 7.2 | 7.2.12 |
| 7.4 | 7.4.8 |
| 7.6 | 7.6.6 |
| 7.7 | 7.7.13 |
| 10.0 | 10.0.2 |
| 10.1 | 10.1.0 |
These are the release figures Cisco lists for its September hardening release, which includes the CVE-2026-20079 fix along with other internally discovered vulnerabilities. Do not assume this table establishes the first-fixed release for CVE-2026-20131: use its current advisory and Software Checker to confirm the relevant train and cumulative exposure.
Rank #2
- Functionality: Centralized Management
- Firewall Protection Supported: Enterprise Security
- Firewall Protection Supported: Threat Protection
- Firewall Protection Supported: Secure IPsec VPN Connectivity
- Firewall Protection Supported: TLS Decryption
Cisco Security Cloud Control
The cloud-managed service is distinct from an on-premises FMC installation. The Singapore agency says Cisco automatically upgraded the relevant Cisco Security Cloud Control component; it required no user action for that cloud-delivered fix. That does not remove the need for organizations running on-premises FMC to check and patch their own deployment.
How should administrators fix the vulnerabilities?
- Identify the deployment. Confirm whether the management system is on-premises FMC or the cloud-managed Cisco Security Cloud Control component, and record the exact installed release and platform.
- Check Cisco’s current guidance. Look up the installed version in the relevant CVE-2026-20079 advisory, CVE-2026-20131 advisory, and Software Checker.
- Upgrade to the appropriate fixed software. Follow Cisco’s version guidance for the exact software train rather than relying only on a general release list.
- If compromise is suspected, contact Cisco TAC. Cisco cautions that a hot fix can prevent future exploitation but may not address an existing compromise.
Cisco says there are no workarounds for either vulnerability. Keeping the FMC management interface off the public internet reduces the attack surface, according to Cisco, but that exposure reduction is not a workaround and does not replace upgrading.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
- Functionality: Centralized Management
- Firewall Protection Supported: Enterprise Security
- Firewall Protection Supported: Threat Protection
- Firewall Protection Supported: Secure IPsec VPN Connectivity
- Firewall Protection Supported: TLS Decryption
What is known about exploitation?
Cisco first published both advisories on March 4, 2026. Its CVE-2026-20131 advisory says PSIRT became aware of attempted exploitation in March. In an update published September 16, Cisco said PSIRT became aware of active exploitation of CVE-2026-20079 in August 2026. Cisco’s September 16 hardening release, updated September 18, provides the release table above. The different wording matters: attempted exploitation of one flaw should not be described as confirmed active exploitation of both.
Quick Recap
Rank #4
- Functionality: Centralized Management
- Firewall Protection Supported: Enterprise Security
- Firewall Protection Supported: Threat Protection
- Firewall Protection Supported: Secure IPsec VPN Connectivity
- Firewall Protection Supported: TLS Decryption
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

