Remote Command Execution Vulnerability in Cisco Secure FMC Software
CVE-2026-20340

8.8HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20340?

A vulnerability in Cisco Secure FMC Software allows an authenticated remote attacker to execute arbitrary commands with root privileges. This issue arises from the insecure deserialization of user-controlled data during web management. By authenticating to the device and sending a specially crafted HTTP payload, an attacker can exploit the vulnerability. If successful, they can save and execute this payload on the operating system at the root level. It is crucial for organizations using Cisco Secure FMC Software to ensure that user accounts have appropriate permissions to mitigate potential risks.

Affected Version(s)

Cisco Secure Firewall Management Center (FMC) 7.0.0

Cisco Secure Firewall Management Center (FMC) 7.0.0.1

Cisco Secure Firewall Management Center (FMC) 7.0.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.