# Cisco firewalls face critical pre-auth RCE flaws

Published: 2026-03-05 · Severity: critical
Canonical: https://vorant.io/reports/c277e97c-2a11-5959-83ad-c849fdd15489/cisco-firewalls-face-critical-pre-auth-rce-flaws

> Cisco patched critical unauthenticated remote code execution vulnerabilities in Secure Firewall Management Center allowing attackers root access via crafted HTTP requests.

Cisco disclosed multiple vulnerabilities affecting its Secure Firewall product line, including two critical pre-authentication remote code execution flaws in Firewall Management Center (FMC). CVE-2026-20079 stems from an improper system process created at boot time, enabling unauthenticated attackers to bypass authentication and execute scripts for root access via crafted HTTP requests. CVE-2026-20131 involves insecure deserialization of user-supplied Java byte streams in the web-based management interface, allowing arbitrary Java code execution as root. Affected products include FMC versions prior to 10.0.1, ASA Software prior to 9.23.1.26, and FTD Software prior to 7.7.11.

The advisory also documents numerous additional vulnerabilities of lower severity, primarily denial-of-service conditions affecting Remote Access SSL VPN functionality, IKEv2 implementations, OSPF features, and the Snort 3 Detection Engine. Several SQL injection, cross-site scripting, and privilege escalation vulnerabilities round out the disclosure. MS-ISAC reports no evidence of active exploitation in the wild. Organizations running affected Cisco firewall products should prioritize patching, particularly for internet-facing management interfaces.

The vulnerabilities span a wide range of Cisco's security infrastructure, from centralized management platforms to core firewall operating systems. The critical RCE flaws in FMC represent a particularly severe risk for organizations that expose management interfaces to untrusted networks, as successful exploitation provides complete device compromise without authentication.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20001, CVE-2026-20002, CVE-2026-20003, CVE-2026-20005, CVE-2026-20006, CVE-2026-20007, CVE-2026-20008, CVE-2026-20013, CVE-2026-20014, CVE-2026-20015, CVE-2026-20016, CVE-2026-20017, CVE-2026-20018, CVE-2026-20020, CVE-2026-20021, CVE-2026-20022, CVE-2026-20023, CVE-2026-20024, CVE-2026-20025, CVE-2026-20039, CVE-2026-20044, CVE-2026-20049, CVE-2026-20050, CVE-2026-20052, CVE-2026-20062, CVE-2026-20063, CVE-2026-20064, CVE-2026-20065, CVE-2026-20066, CVE-2026-20070, CVE-2026-20073, CVE-2026-20079 (templated), CVE-2026-20082, CVE-2026-20100, CVE-2026-20101, CVE-2026-20102, CVE-2026-20103, CVE-2026-20105, CVE-2026-20106, CVE-2026-20131 (KEV)

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-cisco-products-could-allow-for-remote-code-execution_2026-018

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c277e97c-2a11-5959-83ad-c849fdd15489/cisco-firewalls-face-critical-pre-auth-rce-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
