Cisco security advisory (AV26-197) – Update 3

Used in attacksCriticalCVSS 10.0Canadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
CriticalCVSS 10.0
Used in attacks
Yes, 2 of 2 flaws named
Vendors and products
Cisco
Industries
Government
Reported by
1 outlet

On March 4, 2026, Cisco published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:

  • Cisco Security Cloud Control (SCC) Firewall Management – all versions
  • Cisco Secure Firewall Management Center (FMC) – all versions
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14
  • Cisco Secure Firewall Threat Defense (FTD) – all versions

Update 1

On March 18, 2026, Cisco stated that CVE-2026-20131 is being actively exploited.

Update 2

On March 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20131 to their Known Exploited Vulnerabilities (KEV) Database.

Update 3

On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.

Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Vulnerabilities referenced

  • CVE-2026-2007910.0Critical

    Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

    Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

    Used in attacks

    Added to CISA's list 2026-09-09 · Exploit code published · Patch or advisory available

    Full record →
  • CVE-2026-20131Not scored yet

    Cisco Secure Firewall Management Center (FMC)

    Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

    Used in attacksUsed by ransomware gangs

    Added to CISA's list 2026-03-19

    Full record →

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber SecurityOfficial SourceFirst reported

    2026-09-09 20:04 UTC

Related stories