VULNERABILITY OVERVIEW
An insecure deserialization of a user-supplied Java byte stream in the FMC web management interface allows an unauthenticated, remote attacker to execute arbitrary Java code as root. The Interlock ransomware group actively exploited this as a zero-day beginning January 26, 2026 — 36 days before Cisco's official disclosure — targeting education, healthcare, manufacturing, and government sectors. Nine public PoC/exploits are available on GitHub; Zscaler ThreatLabz observed active exploitation payloads using the public PoC starting March 6, 2026. Advisory updated July 29, 2026 with new IoCs shared with CVE-2026-20316.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
Cisco Secure FMC Software versions 6.4.0.13 through 7.7.11; Cisco Security Cloud Control (SCC) Firewall ManagementCITATIONS
- → https://www.zscaler.com/blogs/security-research/critical-remote-code-execution-vulnerability-cisco-secure-firewall
- → https://thehackernews.com/2026/03/interlock-ransomware-exploits-cisco-fmc.html
- → https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20131/
- → https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/