Answer in brief
CVE-2026-20340 records a Unknown severity vulnerability in Cisco Secure Firewall Management Center Software Deserialization Arbitrary Root Command Execution Vulnerability. The current sources do not mark it as known exploited. The current feed maps Cisco/Cisco Secure Firewall Management Center (FMC) (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Cisco/Cisco Secure Firewall Management Center (FMC) (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Cisco/Cisco Secure Firewall Management Center (FMC)generic | 7.0.0 || 7.0.0.1 || 7.0.1 || 7.0.1.1 || 7.0.2 || 7.2.0 || 7.0.2.1 || 7.0.3 || 7.2.0.1 || 7.0.4 || 7.2.1 || 7.0.5 || 7.3.0 || 7.2.2 || 7.3.1 || 7.2.3 || 7.2.3.1 || 7.2.4 || 7.0.6 || 7.2.4.1 || 7.2.5 || 7.3.1.1 || 7.4.0 || 7.0.6.1 || 7.2.5.1 || 7.4.1 || 7.2.6 || 7.4.1.1 || 7.0.6.2 || 7.2.7 || 7.2.5.2 || 7.3.1.2 || 7.2.8 || 7.6.0 || 7.4.2 || 7.2.8.1 || 7.0.6.3 || 7.4.2.1 || 7.2.9 || 7.0.7 || 7.7.0 || 7.4.2.2 || 7.2.10 || 7.6.1 || 7.4.2.3 || 7.0.8 || 7.6.2 || 7.7.10 || 7.2.10.1 || 7.0.8.1 || 7.6.2.1 || 7.2.10.2 || 7.7.10.1 || 7.4.2.4 || 7.4.3 || 7.6.3 || 7.7.11 || 7.6.4 || 10.0.0 || 7.4.4 || 7.4.5 || 7.0.9 || 7.2.11 || 7.7.12 || 7.6.5 || 7.4.6 || 10.0.1 || 7.4.7 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-controlled data. An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP payload. A successful exploit could allow the attacker to save the crafted payload and then execute it on the underlying operating system as root. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Security Analyst (read-only).
Quoted source text, attributed separately from HOL analysis.