Cisco
Cisco Secure Firewall Management Center: vulnerabilidades y CVE
Cisco Secure Firewall Management Center tiene 191 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 9 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE191
Últimos 12 meses9
Críticas9
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-20079 | Crítica (10) | 88% | ⚠ Explotación activa | 4 mar 2026 | — |
| CVE-2026-20316 | Media (5.3) | 35% | ⚠ Explotación activa | 29 jul 2026 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access… |
| CVE-2026-20131 | Crítica (10) | 43% | ⚠ Explotación activa | 4 mar 2026 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-20324 | Crítica (9.9) | 0.45% | — | 16 sept 2026 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This… |
| CVE-2026-20242 | Crítica (9.8) | 0.64% | — | 16 sept 2026 | A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected… |
| CVE-2026-20316 | Media (5.3) | 35% | ⚠ Explotación activa | 29 jul 2026 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access… |
| CVE-2026-20131 | Crítica (10) | 43% | ⚠ Explotación activa | 4 mar 2026 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected… |
| CVE-2026-20079 | Crítica (10) | 88% | ⚠ Explotación activa | 4 mar 2026 | — |
| CVE-2026-20044 | Media (6) | 0.14% | — | 4 mar 2026 | A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to… |
| CVE-2026-20018 | Media (5.9) | 0.42% | — | 4 mar 2026 | A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with… |
| CVE-2026-20003 | Media (4.9) | 0.28% | — | 4 mar 2026 | A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of… |
| CVE-2026-20002 | Alta (8.1) | 0.35% | — | 4 mar 2026 | A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to… |
| CVE-2025-20306 | Media (4.9) | 0.39% | — | 14 ago 2025 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker with Administrator-level privileges to execute arbitrary… |
| CVE-2025-20302 | Media (4.3) | 0.31% | — | 14 ago 2025 | A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to retrieve a generated report from a different domain. This vulnerability… |
| CVE-2025-20301 | Media (6.5) | 0.37% | — | 14 ago 2025 | A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to access troubleshoot files for a different domain. This vulnerability is… |
| CVE-2025-20265 | Crítica (10) | 16% | — | 14 ago 2025 | This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be… |
| CVE-2025-20235 | Media (6.1) | 0.29% | — | 14 ago 2025 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a… |
| CVE-2025-20220 | Media (6) | 0.17% | — | 14 ago 2025 | A vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on… |
| CVE-2025-20218 | Media (4.9) | 0.45% | — | 14 ago 2025 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to retrieve sensitive information from an affected device.… |
| CVE-2025-20148 | Alta (8.5) | 0.46% | — | 14 ago 2025 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated… |
| CVE-2021-34751 | Media (4.3) | 0.28% | — | 15 nov 2024 | — |
| CVE-2021-34750 | Media (4.3) | 0.28% | — | 15 nov 2024 | A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center Software could allow an authenticated, remote attacker to access sensitive configuration information. The… |
| CVE-2024-20482 | Media (6.5) | 0.49% | — | 23 oct 2024 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate… |
| CVE-2024-20473 | Media (6.5) | 0.44% | — | 23 oct 2024 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This… |
| CVE-2024-20472 | Media (6.5) | 0.44% | — | 23 oct 2024 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This… |
| CVE-2024-20471 | Media (6.5) | 0.44% | — | 23 oct 2024 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This… |
| CVE-2024-20424 | Crítica (9.9) | 0.94% | — | 23 oct 2024 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute… |
| CVE-2024-20415 | Media (6.1) | 0.31% | — | 23 oct 2024 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of… |
| CVE-2024-20410 | Media (6.1) | 0.31% | — | 23 oct 2024 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of… |
| CVE-2024-20409 | Media (6.1) | 0.31% | — | 23 oct 2024 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of… |
| CVE-2024-20403 | Media (5.4) | 0.29% | — | 23 oct 2024 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of… |
| CVE-2024-20388 | Media (5.3) | 0.41% | — | 23 oct 2024 | A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability… |
| CVE-2024-20387 | Media (5.4) | 0.29% | — | 23 oct 2024 | A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.