HomeSecurityCisco Secure FMC: Vulnerability allows RCE attacks

Cisco Secure FMC: Vulnerability allows RCE attacks

Cybersecurity remains an ever-evolving challenge for organizations and businesses, especially when it comes to critical network infrastructure. In this context, Cisco has issued an urgent advisory for a particularly serious vulnerability affecting the Secure Firewall Management Center (FMC) software , causing great concern among system administrators.

Cisco Secure FMC

Critical vulnerability in Cisco Secure Firewall Management Center

The issue is located in the Cisco Secure Firewall Management Center (FMC), the platform used to centrally manage and monitor Cisco firewall systems. According to the company, the vulnerability could allow remote and unauthorized attackers to execute arbitrary code on the system.

The severity of the issue is also reflected in its Common Vulnerability Scoring System (CVSS) score, where it received the maximum possible score of 10.0. This means that the vulnerability can be exploited remotely, without requiring prior access or user interaction.

See also: IPVanish VPN for macOS: Vulnerability allows privilege escalation

If successfully exploited, an attacker could gain full privileges (root) on the affected system, essentially gaining complete control over the firewall management device.

How this security hole works

The vulnerability is related to an insecure deserialization in the system management web interface. More specifically, the software processes user-supplied Java byte streams without adequate security checks.

This means that an attacker can create a specially crafted serialized Java object and send it via the web interface. If the system successfully processes it, executed malicious code on the underlying operating system.

The execution is performed with root privileges, which gives the attacker full access to the device and the ability to modify critical security functions.

Cisco Secure FMC: Vulnerability allows RCE attacks

Why compromising a firewall management system is so dangerous

A system like the Secure Firewall Management Center is the "heart" of network management in many organizations. It is from there that security policies, firewall rules, and threat protection mechanisms are controlled

See also: VMware Aria Operations vulnerability on CISA's KEV List

If an attacker gains access to this level, they can modify security settings, disable critical defenses , or even create new “backdoors” into the network.

Even more worrying is the fact that such a device could be used as a launching point for further attacks within a corporate environment. Attackers could move laterally through the network and gain access to internal servers or databases.

The discovery of the vulnerability and the current status

The vulnerability was discovered by security researcher Keane O'Kelley, a member of the Cisco Advanced Security Initiatives Group (ASIG), during the company's internal security testing.

The Cisco Product Security Incident Response Team (PSIRT) said that so far there is no evidence of the vulnerability being actively exploited in real-world attacks. However, the severity of the vulnerability makes it a potential target for cybercriminal groups.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In particular, ransomware groups or attackers supported by state mechanisms often target such critical infrastructure.

Which systems are affected?

The vulnerability affects both Cisco Secure FMC software and firewall management systems that operate through the Cisco Security Cloud Control (SCC) platform.

See also: Google: Vulnerability in Qualcomm Android Component used by hackers

Cisco clarified that the issue occurs regardless of device configuration, meaning multiple deployment environments are affected.

In contrast, two other key products of the company are not affected by this vulnerability: the Cisco Adaptive Security Appliance (ASA) and the Cisco Firepower Threat Defense (FTD).

Cisco Secure FMC: Vulnerability allows RCE attacks

The absence of temporary solutions

One of the most concerning aspects of the announcement is that there are no workarounds or mitigation techniques available for the vulnerability. This means that organizations cannot protect themselves simply by changing settings or limiting certain functions.

The only effective solution is to immediately install the official software updates that Cisco has made available to address the problem.

What should organizations do?

Cybersecurity teams are urged to immediately review Cisco's updated security advisory package for March 2026 and proceed with the necessary upgrades.

Rapid implementation of updates is considered critical, as vulnerabilities with a CVSS score of 10.0 quickly become attack toolsonce technical details are made public.

In an environment where attacks on corporate networks are constantly increasing, timely management of such security gaps can be the difference between a simple software update and a serious data breach.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS