Remote Command Execution Vulnerability in Cisco Secure FMC Software
CVE-2026-20340
What is CVE-2026-20340?
A vulnerability in Cisco Secure FMC Software allows an authenticated remote attacker to execute arbitrary commands with root privileges. This issue arises from the insecure deserialization of user-controlled data during web management. By authenticating to the device and sending a specially crafted HTTP payload, an attacker can exploit the vulnerability. If successful, they can save and execute this payload on the operating system at the root level. It is crucial for organizations using Cisco Secure FMC Software to ensure that user accounts have appropriate permissions to mitigate potential risks.
Affected Version(s)
Cisco Secure Firewall Management Center (FMC) 7.0.0
Cisco Secure Firewall Management Center (FMC) 7.0.0.1
Cisco Secure Firewall Management Center (FMC) 7.0.1