Cisco security advisory (AV26-197) – Update 3
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-197 Date: March 5, 2026 Updated: September 9, 2026 On March 4, 2026, Cisco published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: Cisco Security Cloud Control (SCC) Firewall Management – all versions Cisco Secure Firewall Management Center (FMC) – all versions Cisco Secure Firewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions Update 1 On March 18, 2026, Cisco stated that CVE-2026-20131 is being actively exploited. Update 2 On March 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20131 to their Known Exploited Vulnerabilities (KEV) Database. Update 3 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available. Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability Cisco Secure Firewall Adaptive Security Appliance Software TCP Flood Denial of Service Vulnerability Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability Cisco Security Advisories CISA KEV: CVE-2026-20131 CISA KEV: CVE-2026-20079
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-197
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-20131Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 98% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-20079Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.5% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20131 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20079 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploited[UPDATE] [kritisch] Cisco Secure Firewall Management Center: Mehrere Schwachstellencert-bund
- criticalexploitedCisco Secure Firewall Management Center Software Authentication Bypass Vulnerabilitycisco-psirt
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vuln…cisa-kev
- criticalexploitedCVE-2026-20131: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) …cisa-kev
More from Canadian Centre for Cyber Security
- unknownFortra security advisory (AV26-906)2026-09-10
- unknownPalo Alto Networks security advisory (AV26-905)2026-09-10
- unknownAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-…2026-09-09
- unknownCitrix security advisory (AV26-833) - Update 12026-09-09
- criticalFortinet security advisory (AV26-023) - Update 12026-09-09