Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Cisco warns of max severity Secure FMC flaws giving root access
    Cybersecurity

    Cisco warns of max severity Secure FMC flaws giving root access

    adminBy adminMarch 4, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Cisco
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cisco

    Cisco has released security updates to patch two maximum-severity vulnerabilities in its Secure Firewall Management Center (FMC) software.

    Secure FMC is a web or SSH-based interface for admins to manage Cisco firewalls and configure application control, intrusion prevention, URL filtering, and advanced malware protection.

    Both vulnerabilities can be exploited remotely by unauthenticated attackers: the authentication bypass flaw (CVE-2026-20079) allows attackers to gain root access to the underlying operating system, while the remote code execution (RCE) vulnerability (CVE-2026-20131) lets them execute arbitrary Java code as root on unpatched devices.

    “An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device,” the CVE-2026-20079 advisory reads.

    “An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root,” Cisco added about CVE-2026-20079.

    While they both affect Cisco Secure FMC Software, CVE-2026-20131 also affects Cisco Security Cloud Control (SCC) Firewall Management, a cloud-based security policy manager that simplifies policy across Cisco firewalls and other devices.

    At the moment, the company’s Product Security Incident Response Team (PSIRT) has no evidence that the two security flaws are exploited in attacks or that proof-of-concept (PoC) exploit code has been published online.

    Today, Cisco has also patched dozens of other security vulnerabilities, including 15 high-severity security flaws in Secure FMC, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense software.

    In August, Cisco fixed another maximum-severity Secure FMC flaw, warning that it allows unauthenticated remote attackers to inject arbitrary shell commands that are executed on unpatched devices.

    More recently, in January, it released patches for a maximum-severity Cisco AsyncOS zero-day that has been exploited in attacks against secure email appliances since November and addressed a critical Unified Communications RCE that was also used in zero-day attacks.

    Last month, it also patched a maximum-severity Catalyst SD-WAN authentication bypass flaw that was abused as a zero-day, allowing remote attackers to compromise controllers and add malicious rogue peers to targeted networks.


    tines

    Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

    Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.

    access Cisco Flaws FMC giving Max root secure severity warns
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleWhy Your Content Loses Accuracy & How to Fix It
    Next Article Cato Networks brings adaptive threat defense to SASE
    admin
    • Website

    Related Posts

    149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict

    March 4, 2026

    Tufin’s AI-powered tools simplify network security operations

    March 4, 2026

    Iran-nexus hackers target flaws in surveillance cameras

    March 4, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict

    March 4, 2026

    Google Ads status dashboard flags Ad Manager reporting issue

    March 4, 2026

    The Amazon Fire TV Stick 4K Plus is a whopping 40% off right now

    March 4, 2026

    Tufin’s AI-powered tools simplify network security operations

    March 4, 2026
    Categories
    • Blogging (33)
    • Cybersecurity (604)
    • Privacy & Online Earning (91)
    • SEO & Digital Marketing (381)
    • Tech Tools & Mobile / Apps (740)
    • WiFi / Internet & Networking (108)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict

    March 4, 2026

    Google Ads status dashboard flags Ad Manager reporting issue

    March 4, 2026

    The Amazon Fire TV Stick 4K Plus is a whopping 40% off right now

    March 4, 2026
    Most Popular
    • 149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict
    • Google Ads status dashboard flags Ad Manager reporting issue
    • The Amazon Fire TV Stick 4K Plus is a whopping 40% off right now
    • Tufin’s AI-powered tools simplify network security operations
    • ‘We wanted something that felt fun and friendly, and fresh, and felt like it really suited the spirit of this product’: Apple exec on why their new budget laptop is called MacBook Neo
    • A Comprehensive Guide to Every Ping Utility
    • Iran-nexus hackers target flaws in surveillance cameras
    • Speaking Freely: Shin Yang | Electronic Frontier Foundation
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.