Cyber Security News

Cisco Secure Firewall Management Vulnerability Enables Remote Code Execution

Cisco has issued an urgent security advisory for a critical vulnerability affecting its Secure Firewall Management Center (FMC) software.

This flaw, rated with the maximum possible CVSS score of 10.0, allows remote, unauthenticated attackers to execute arbitrary code and gain complete root-level control over the affected system. The vulnerability exists in the web-based management interface of Cisco Secure FMC.

The flaw stems from insecure deserialization of a user-supplied Java byte stream, allowing attackers to send a specially crafted serialized Java object to the web interface to exploit it

If successful, the exploit allows the attacker to run arbitrary Java code on the underlying operating system. Because the code executes with root-level privileges, the attacker could gain total control over the management device.

Cisco Secure Firewall Management Vulnerability

A CVSS score of 10.0 indicates the highest possible severity, meaning the attack requires no user interaction and no prior authentication. It can be launched remotely over the network.

Taking control of a firewall management system is particularly dangerous, as it could allow an attacker to alter security policies and turn off network defenses.

Use the management center as a pivot point to launch further attacks deep into an internal network.​ This flaw was discovered during internal security testing by Keane O’Kelley from the Cisco Advanced Security Initiatives Group (ASIG).

Currently, Cisco’s Product Security Incident Response Team (PSIRT) reports that it is not aware of any active exploitation or malicious use of this vulnerability in the wild.​

The flaw impacts both Cisco Secure FMC Software and Cisco Security Cloud Control (SCC) Firewall Management systems, regardless of how the devices are configured.

However, Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software are confirmed not to be vulnerable to this specific issue.​

There are no workarounds available to mitigate this threat. Organizations must apply the official software updates provided by Cisco to protect their environments.​

Security teams are strongly advised to review the March 2026 Cisco Secure Firewall advisory bundle to address this and other potential flaws.

Although no active exploitation is seen yet, a CVSS 10.0 flaw makes it a likely target for ransomware and nation-state attackers, making prompt remediation critical.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago