CVE-2026-20002 HIGH

CVE-2026-20002

Vendor Cisco
Product Cisco Secure Firewall Management Center (FMC)
Weakness CWE-89 · SQLi
Published March 4, 2026
Last update March 5, 2026

CVSS base score

8.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an affected device. A successful exploit could allow the attacker to obtain full access to the database and read certain files on the underlying operating system. To exploit this vulnerability, the attacker would need valid user credentials.

Key dates

02Disclosure timeline

March 4, 2026 CVE published
March 5, 2026 Record updated