Description
A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level.

This vulnerability is due to unsecured deserialization of web-management user-controlled data. An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP payload. A successful exploit could allow the attacker to save the crafted payload and then execute it on the underlying operating system as root.
To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Security Analyst (read-only).
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Root Command Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in Cisco Secure FMC software allows an attacker who can authenticate with a user account of at least Security Analyst level (read‑only) to send a crafted HTTP payload to the web‑management interface. The server deserializes this user‑controlled data without proper validation, enabling the attacker to save the payload and then execute it on the underlying operating system with root privileges. The vulnerability is therefore a high‑severity root‑command execution risk that can compromise the entire FMC system and any connected network devices.

Affected Systems

The affected product is Cisco Secure Firewall Management Center, commonly known as FMC. No specific version range is listed in the advisory, so all deployed instances are potentially vulnerable until a patch is applied or the vulnerable feature is disabled.

Risk and Exploitability

The CVSS score of 8.8 indicates a high likelihood of successful exploitation if a valid credential is available. The EPSS score of less than 1% suggests a very low probability of observed exploitation at this time, and the vulnerability is not yet catalogued in the CISA KEV list. However, because the attack requires a legitimate user’s credentials, an internal threat actor or an attacker who has compromised an account can deploy the payload over the web interface, gain root access, and potentially compromise the entire network infrastructure. The existing weak deserialization mechanism is the root cause, and the attack vector is authenticated remote web‑based exploitation.

Generated by OpenCVE AI on September 18, 2026 at 00:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco Secure FMC firmware update that contains the deserialization fix referenced in the Cisco Security Advisory.
  • Limit access to the FMC web‑management console to trusted networks and enable multi‑factor authentication to reduce the chance of unauthorized credential compromise.
  • Enforce least‑privilege by restricting or removing Security Analyst role accounts from the web interface when they are not needed, and use stricter administrative roles only for critical operations.

Generated by OpenCVE AI on September 18, 2026 at 00:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Management Center
Vendors & Products Cisco
Cisco secure Firewall Management Center

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the&nbsp;root privilege level. This vulnerability is due to unsecured deserialization of web-management user-controlled data. An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP payload. A successful exploit could allow the attacker to save the crafted payload and then execute it on the underlying operating system as root. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Security Analyst (read-only).
Title Cisco Secure Firewall Management Center Software Deserialization Arbitrary Root Command Execution Vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Secure Firewall Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T03:56:07.878Z

Reserved: 2025-10-08T11:59:15.413Z

Link: CVE-2026-20340

cve-icon Vulnrichment

Updated: 2026-09-17T16:02:25.178Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:11.560

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:11Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data