CVE-2026-20131

CRITICAL KEV RANSOMWARE LAB

Cisco Secure Firewall Management Center 6.4.0.13-6.4.0.18, 7.0.0 - RCE via Java Deserialization

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-20131 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 19, 2026, with confirmed use in ransomware campaigns. EIP tracks 7 public exploits from researchers including XiaomingX, adminlove520, 0xBlackash.

AI-analyzed exploit summary The repository contains obfuscated Python code using PyArmor, which is highly unusual for legitimate PoCs. The lack of readable exploit logic and the presence of obfuscation suggest malicious intent.

Description

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Exploits (7)

github TROJAN 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-20131

The repository contains obfuscated Python code using PyArmor, which is highly unusual for legitimate PoCs. The lack of readable exploit logic and the presence of obfuscation suggest malicious intent.

Classification
Trojan 95%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: unknown
No auth needed
Prerequisites: none identifiable
devstral-2 · analyzed Mar 07, 2026 Full analysis →
github WRITEUP 3 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2026/CVE-2026-20131

This repository provides a detailed technical writeup and implementation of a low-interaction honeypot designed to mimic a Cisco Secure Firewall Management Center (FMC) web surface. It captures unauthenticated Java serialization-style attack traffic by detecting specific magic bytes and extracting shell or URL strings using regular expressions and heuristics, without actually deserializing Java objects.

Classification
Writeup 95%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Cisco Secure Firewall Management Center (FMC)
No auth needed
Prerequisites: Docker and Docker Compose v2 · VPS or isolated network segment · Domain for HTTPS (optional)
devstral-2 · analyzed May 04, 2026 Full analysis →
nomisec SCANNER
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2026-20131

The repository contains a Python script that checks for the presence of CVE-2026-20131 in Cisco Secure Firewall Management Center (FMC) by probing known endpoints for Java deserialization responses. It does not include an exploit payload, only detection logic.

Classification
Scanner 100%
Attack Type
Deserialization
Complexity
Trivial
Reliability
Reliable
Target: Cisco Secure Firewall Management Center (FMC)
No auth needed
Prerequisites: network access to the target FMC instance
devstral-2 · analyzed May 11, 2026 Full analysis →
nomisec WORKING POC
by Hassan-Pouladi · poc
https://github.com/Hassan-Pouladi/Cisco-FMC-honeypot

This repository contains a low-interaction honeypot designed to mimic a Cisco Secure Firewall Management Center (FMC) web surface and capture unauthenticated Java serialization-style attack traffic. It detects and logs deserialization probes without executing malicious payloads, making it a functional proof-of-concept for studying CVE-2026-20131.

Classification
Working Poc 95%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Cisco Secure Firewall Management Center (FMC)
No auth needed
Prerequisites: Docker and Docker Compose v2 · VPS or isolated network segment · Optional domain for HTTPS
devstral-2 · analyzed Apr 09, 2026 Full analysis →
nomisec WORKING POC
by sak110 · poc
https://github.com/sak110/CVE-2026-20131

This repository contains a functional exploit PoC for CVE-2026-20131, a critical Java deserialization vulnerability in Cisco Secure Firewall Management Center (FMC) Software. It includes a detection script (`check.py`) and a full exploit (`poc.py`) leveraging ysoserial for unauthenticated remote code execution as root.

Classification
Working Poc 95%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Cisco Secure Firewall Management Center (FMC) Software
No auth needed
Prerequisites: Network access to the FMC web interface · Python environment with `requests` library · ysoserial for payload generation
devstral-2 · analyzed Mar 11, 2026 Full analysis →
nomisec TROJAN
by p3Nt3st3r-sTAr · poc
https://github.com/p3Nt3st3r-sTAr/CVE-2026-20131-POC

The repository contains obfuscated Python code using PyArmor, which is highly suspicious and indicative of malicious intent. The lack of readable exploit logic and the use of obfuscation tools suggest deception.

Classification
Trojan 95%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: unknown
No auth needed
Prerequisites: none identifiable
devstral-2 · analyzed Mar 06, 2026 Full analysis →
nomisec SCANNER
by Sushilsin · poc
https://github.com/Sushilsin/CVE-2026-20131

The repository contains a detection script for CVE-2026-20131, which targets insecure Java deserialization in Cisco Secure Firewall Management Center (FMC). The script probes known endpoints with Java serialization magic bytes to identify potential vulnerability without executing an exploit.

Classification
Scanner 95%
Attack Type
Deserialization
Complexity
Trivial
Reliability
Reliable
Target: Cisco Secure Firewall Management Center (FMC)
No auth needed
Prerequisites: Network access to the target FMC interface
devstral-2 · analyzed Mar 06, 2026 Full analysis →

Scores

CVSS v3 10.0
EPSS 0.0172
EPSS Percentile 82.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-03-19
VulnCheck KEV 2026-03-18
ENISA EUVD EUVD-2026-9444
Ransomware Use Confirmed
CWE
CWE-502
Status published
Products (50)
Cisco/Cisco Secure Firewall Management Center (FMC) 10.0.0
Cisco/Cisco Secure Firewall Management Center (FMC) 6.4.0.13
Cisco/Cisco Secure Firewall Management Center (FMC) 6.4.0.14
Cisco/Cisco Secure Firewall Management Center (FMC) 6.4.0.15
Cisco/Cisco Secure Firewall Management Center (FMC) 6.4.0.16
Cisco/Cisco Secure Firewall Management Center (FMC) 6.4.0.17
Cisco/Cisco Secure Firewall Management Center (FMC) 6.4.0.18
Cisco/Cisco Secure Firewall Management Center (FMC) 7.0.0
Cisco/Cisco Secure Firewall Management Center (FMC) 7.0.0.1
Cisco/Cisco Secure Firewall Management Center (FMC) 7.0.1
... and 40 more
Published Mar 04, 2026
KEV Added Mar 19, 2026
Tracked Since Mar 05, 2026