Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Cisco Secure Firewall Management Center Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary Java code with root privileges on the affected device. The issue arises from insecure deserialization of user-supplied Java byte streams. Exploitation involves sending a crafted serialized Java object to the management interface. Note that the vulnerability's impact is reduced if the FMC management interface lacks public internet access.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected device, with elevated privileges to root.

Remediation

Cisco has released software updates to address this vulnerability. For guidance on upgrading to a fixed software release, Cisco recommends using the Cisco Software Checker tool, which identifies relevant security advisories and the earliest fixed release. Additional resources are available for help with Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software releases.

Added: Mar 4, 2026, 6:34 PM
Updated: Mar 19, 2026, 3:29 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
8.9
remediation
0.0
relevance
3.5
threat
8.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.