Technical Severity
CRITICALCVSS v3.1 Metrics
10
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitation Likelihood
EPSS Prediction
0.60
%
Predictive Probability
Percentile Rank
69.2
th
Documented as more likely to be exploited than 69.2% of known CVEs.
Detection Date
Mar 19, 2026
Remediation Due
Mar 22, 2026
CISA Catalog Active
Threat Analysis
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
Remediation Directive
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.