CVE-2026-20131 is a CVSS 10.0 insecure deserialization vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. The interface deserializes a user-supplied Java byte stream without adequate validation. An unauthenticated remote attacker can submit a crafted serialized Java object to cause arbitrary Java code execution as root on the FMC appliance. The vulnerability was publicly disclosed in March 2026 and has been reported as exploited as a zero-day by the Interlock ransomware operation beginning in January 2026.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
Repository contains a detection script and an RCE PoC for CVE-2026-20131 (Cisco Secure Firewall Management Center Java deserialization). Structure: (1) README.md documents the vulnerability, affected products, and usage. (2) check.py is a safe network probe that POSTs Java serialization magic bytes (0xACED0005) with Content-Type application/x-java-serialized-object to several FMC endpoints (/j_spring_security_check, /api/fmc_platform/v1/auth/generatetoken, /dispatcher, /invoker/JMXInvokerServlet, /invoker/EJBInvokerServlet) and flags HTTP 500/200 as potential deserialization handling. (3) poc.py is an operational PoC exploit that generates a malicious serialized object using an external tool (ysoserial-all.jar executed via local Java) with selectable gadget chains (CommonsCollections*, Spring*, Groovy1) and an attacker-supplied command, then POSTs the payload to likely deserialization endpoints. The exploit is unauthenticated and intended to achieve blind command execution (often inferred from HTTP 500 and/or out-of-band callbacks such as reverse shells or DNS). No persistence is implemented; payload is arbitrary command execution.
Repository contains a claimed working PoC exploit for CVE-2026-20131 targeting Cisco Catalyst SD-WAN Controller (vSmart) and Catalyst SD-WAN Manager (vManage). Structure: (1) `CVE-2026-20131-POC.py` is the main exploit entry point but is PyArmor-obfuscated/encrypted, preventing static extraction of exact request paths, parameters, or hardcoded targets from the provided content. (2) `cmd.jsp` is a JSP webshell payload that executes arbitrary OS commands supplied via the `cmd` HTTP parameter using `bash -c`, returning both stdout and stderr—indicative of post-exploitation persistence/command execution. (3) `README.md` describes capabilities: pre-auth auth bypass, admin privilege gain, ability to create a rogue peer in the SD-WAN control/management plane, and access to NETCONF on TCP/830. Fingerprintable observables available from the repo content are limited to the Telegram URL and the NETCONF port reference; any additional exploit endpoints (e.g., specific vManage/vSmart API paths) are likely embedded inside the obfuscated Python script and are not visible here.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
229 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate Cisco FMC zero-day mentioned as background context; it was reportedly exploited by the Interlock ransomware group earlier in 2026.
A Cisco security vulnerability addressed in Cisco's March 4, 2026 advisories that Cisco stated was under active exploitation and that CISA added to the KEV catalog.
An authentication-bypass vulnerability in Cisco Secure Firewall Management Center (FMC) Software. Cisco stated it is actively exploited, and CISA added it to the KEV catalog.
A critical-severity zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software that the Interlock ransomware threat actor was actively exploiting.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.