Cisco security advisory (AV26-197) – Update 3
On March 4, 2026, Cisco published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:
- Cisco Security Cloud Control (SCC) Firewall Management – all versions
- Cisco Secure Firewall Management Center (FMC) – all versions
- Cisco Secure Firewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14
- Cisco Secure Firewall Threat Defense (FTD) – all versions
Update 1
On March 18, 2026, Cisco stated that CVE-2026-20131 is being actively exploited.
Update 2
On March 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20131 to their Known Exploited Vulnerabilities (KEV) Database.
Update 3
On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.
- Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
- Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
- Cisco Secure Firewall Adaptive Security Appliance Software TCP Flood Denial of Service Vulnerability
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability
- Cisco Security Advisories
- CISA KEV: CVE-2026-20131
- CISA KEV: CVE-2026-20079
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
At a glance
- Severity
- Criticalhighest referenced CVSS 10.0
- Exploitation
- Confirmed — 2 of 2 referenced vulnerabilities are on the CISA Known Exploited Vulnerabilities catalogue
- Vulnerabilities
- CVE-2026-20079CVE-2026-20131
- Vendors & products
- Cisco
- Threat actors & malware
- None named
- Industries
- Government
- Coverage
- 1 outlet· first seen 2026-09-09 20:04 UTC
- Priority
- 100/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.
Vulnerabilities referenced
- CVE-2026-20079Exploited· due 2026-09-12Critical10.0
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
Added to KEV 2026-09-09
Full record → - CVE-2026-20131Exploited· due 2026-03-22
Cisco Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
Used in ransomware · Added to KEV 2026-03-19
Full record →
Coverage
One outlet has carried this so far.
2026-09-09 20:04 UTC
Related stories
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The Hacker News · 2026-09-12
- GitLab security advisory (AV26-917)
Canadian Centre for Cyber Security · 2026-09-11
- Hackers abused Claude to extract secrets from 1.8M Android apps
BleepingComputer · 2026-09-11
- n8n security advisory (AV26-916)
Canadian Centre for Cyber Security · 2026-09-11
- Progress security advisory (AV26-915)
Canadian Centre for Cyber Security · 2026-09-11