CVE-2026-20001Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an affected device. A successful exploit could allow the attacker to obtain read access to the database and read certain files on the underlying operating system. To exploit this vulnerability, the attacker would need valid user credentials with any of the following roles: Administrator Security approver Access admin Network admin

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-04); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-03-04: 103-0403-05
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-041
Disclosure1
2026-03-051
Patch1
Full discourse2 posts
  • Fernando Karl@fernandokarl
    Patch

    ⚠️ Importante! A injeção SQL na REST API do Cisco Secure FMC pode expor dados sensíveis. Admins, é hora de agir! Aplique patches, restrinja acessos e habilite MFA! Quais são suas práticas de segurança? 🛡️ #CyberSecurity #SQLInjection #Cisco 👉 https://www.tenable.com/cve/CVE-2026-20001

    Post summary

    The post alerts administrators to a CVE-2026-20001 SQL injection in Cisco Secure FMC’s REST API, urging them to apply patches, restrict access, and enable MFA to mitigate risk.

    0000053
    254 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20001 A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. … https://www.cve.org/CVERecord?id=CVE-2026-20001

    Post summary

    The announcement details CVE-2026-20001, a SQL injection vulnerability in Cisco Secure FMC Software’s REST API that permits authenticated remote attackers to execute injections.

    00000129
    56.6K followersView on X

Explore more