Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Cisco reveals 2 max-severity defects in firewall management software  – CyberScoop
AttackFeed by Joe Wagner | Cisco reveals 2 max-severity defects in firewall management software  - CyberScoop

Cisco reveals 2 max-severity defects in firewall management software  – CyberScoop

Posted on March 5, 2026 By Matt Kapko
Attack Feeds

Cisco released information on a pair of max-severity vulnerabilities in its firewall management software Wednesday that unauthenticated, remote attackers could exploit to obtain the highest level of access to the underlying operating system or on affected devices.

The vulnerabilities — CVE-2026-20079 and CVE-2026-20131 — affect the web-based interface of Cisco Secure Firewall Management Center (FMC) Software, regardless of device configuration, the vendor said.

Cisco disclosed the critical vulnerabilities one week after it warned that attackers have been exploiting a pair of zero-days in Cisco’s network edge software for at least three years. That campaign, which is ongoing, marked the second series of multiple actively exploited zero-days in Cisco edge technology since last spring. 

Both campaigns prompted the Cybersecurity and Infrastructure Security Agency to issue emergency directives months after the attacks were first detected, and both attack sprees were underway for at least a year before they were discovered. 

Cisco said the new vulnerabilities were disclosed and patched as part of its biannual update, which contained 48 vulnerabilities across multiple security products.

“At the time of publication, Cisco PSIRT (public security incident response team) is not aware of any malicious use of these vulnerabilities,” a company spokesperson told CyberScoop. 

“We strongly urge customers to upgrade to available fixed software releases that address these vulnerabilities,” the spokesperson added. 

One of the vulnerabilities in Cisco Secure FMC Software — CVE-2026-20079 — allows attackers to bypass authentication and execute script files on an affected device to obtain root access to the operating system. 

“This vulnerability is due to an improper system process that is created at boot time,” Cisco said in a security advisory.

Cisco said the second critical defect — CVE-2026-20131 — is a deserialization flaw that allows attackers to achieve remote code execution. 

“An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device,” the vendor said in a security advisory. “A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.”

Cisco describes the affected product as the “administrative nerve center” for firewall management, application control, intrusion prevention, URL filtering and malware protection.

There are no workarounds for either vulnerability. Cisco did not say how the vulnerabilities might be related, if they can be chained together for exploitation, nor when and under what circumstances it became aware of the defects.

The post Cisco reveals 2 max-severity defects in firewall management software appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Preparing for the Quantum Era: Post-Quantum Cryptography Webinar for Security Leaders  – The Hacker News
Next Post: LeakBase Cybercrime and Hacker Forum Seized  – Hackread – Cybersecurity News, Data Breaches, AI and More ❯

You may also like

AttackFeed by Joe Wagner | From Ransomware to Residency: Inside the Rise of the Digital Parasite  - The Hacker News
Attack Feeds
From Ransomware to Residency: Inside the Rise of the Digital Parasite  – The Hacker News
February 10, 2026
AttackFeed by Joe Wagner | Leading Myanmar Fleet Management Company Yoma Fleet Selects AccuKnox SIEM to Replace Legacy Tools  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Leading Myanmar Fleet Management Company Yoma Fleet Selects AccuKnox SIEM to Replace Legacy Tools  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 10, 2026
AttackFeed by Joe Wagner | 24/7 Payments for 24/7 Agents: The Case for Crypto in the Machine Economy  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
24/7 Payments for 24/7 Agents: The Case for Crypto in the Machine Economy  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 30, 2026
AttackFeed by Joe Wagner | New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption  - The Hacker News
Attack Feeds
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption  – The Hacker News
May 14, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.