Cisco Firepower Management Center (FMC)

Our sources currently list 182 known vulnerabilities affecting Cisco Firepower Management Center (FMC). 6 are rated critical severity. 1 of 182 is actively exploited according to CISA, the most recent added 19 March 2026.

Last updated: 22 July 2026, 20:04 AEST

No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.

Known vulnerabilities in Cisco Firepower Management Center (FMC), highest risk first.Showing the 50 highest-risk of 182 total.
CVESeverityExploitationPublishedSummary
CVE-2026-20131Critical (10.0)Actively exploited · ransomwareA vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary…
CVE-2016-6433High (8.8)Elevated likelihood (76%)The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application p…
CVE-2016-6435Medium (6.5)Elevated likelihood (37%)The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.
CVE-2023-20048Critical (9.9)Elevated likelihood (16%)A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized conf…
CVE-2025-20265Critical (10.0)Elevated likelihood (15%)A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary…
CVE-2019-1978Medium (5.8)No exploitation reportedA vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Soft…
CVE-2019-15992High (7.2)No exploitation reportedA vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could …
CVE-2019-12691Medium (4.9)No exploitation reportedA vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory trave…
CVE-2019-1642Medium (6.1)No exploitation reportedA vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to conduct a cross-site sc…
CVE-2022-20743Medium (6.5)No exploitation reportedA vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to bypass security protections and…
CVE-2016-1457High (8.8)No exploitation reportedThe web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices wi…
CVE-2019-12690High (7.2)No exploitation reportedA vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with the p…
CVE-2019-12687High (8.8)No exploitation reportedA vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The …
CVE-2019-12688High (8.8)No exploitation reportedA vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The …
CVE-2019-16028Critical (9.8)No exploitation reportedA vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execut…
CVE-2019-12689High (8.8)No exploitation reportedA vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on…
CVE-2018-15458Medium (5.3)No exploitation reportedA vulnerability in the Shell Access Filter feature of Cisco Firepower Management Center (FMC), when used in conjunction with remote authentication, could allow an unauthenticated, …
CVE-2018-0383High (8.6)No exploitation reportedA vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the t…
CVE-2016-6368High (8.6)No exploitation reportedA vulnerability in the detection engine parsing of Pragmatic General Multicast (PGM) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote att…
CVE-2019-12679High (8.8)No exploitation reportedMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrar…
CVE-2019-12680High (8.8)No exploitation reportedMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrar…
CVE-2019-12681High (8.8)No exploitation reportedMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrar…
CVE-2019-12682High (8.8)No exploitation reportedMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrar…
CVE-2019-12683High (8.8)No exploitation reportedMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrar…
CVE-2019-12684High (8.8)No exploitation reportedMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrar…
CVE-2019-12685High (8.8)No exploitation reportedMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrar…
CVE-2019-12686High (8.8)No exploitation reportedMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrar…
CVE-2018-0384Medium (5.8)No exploitation reportedA vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a URL-based access control policy that is confi…
CVE-2018-0233High (8.6)No exploitation reportedA vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote …
CVE-2016-1458High (8.8)No exploitation reportedThe web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Soft…
CVE-2021-40114Medium (6.8)No exploitation reportedMultiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a…
CVE-2018-0385High (7.5)No exploitation reportedA vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker …
CVE-2020-3550High (8.1)No exploitation reportedA vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attac…
CVE-2018-0278Medium (6.5)No exploitation reportedA vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data about the system. The vulnerab…
CVE-2018-0370High (7.5)No exploitation reportedA vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause one of the detection engine processes to run out…
CVE-2017-3809Medium (5.8)No exploitation reportedA vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete a…
CVE-2020-3315Medium (5.3)No exploitation reportedMultiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on…
CVE-2021-1236Medium (5.3)No exploitation reportedMultiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured poli…
CVE-2021-1224Medium (5.8)No exploitation reportedMultiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remot…
CVE-2021-1223High (7.5)No exploitation reportedMultiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HT…
CVE-2016-9193High (7.5)No exploitation reportedA vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remot…
CVE-2020-3499High (8.6)No exploitation reportedA vulnerability in the licensing service of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) cond…
CVE-2018-0333Medium (5.8)No exploitation reportedA vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side…
CVE-2019-12700Medium (6.5)No exploitation reportedA vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Sof…
CVE-2017-3814Medium (5.8)No exploitation reportedA vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to block certain web content, aka a…
CVE-2019-1696High (7.5)No exploitation reportedMultiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, …
CVE-2020-3302High (8.1)No exploitation reportedA vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to overwrite files on the file system of an affected…
CVE-2019-1833Medium (5.8)No exploitation reportedA vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol parser of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, re…
CVE-2021-34749Medium (5.8)No exploitation reportedA vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine co…
CVE-2019-1832Medium (5.8)No exploitation reportedA vulnerability in the detection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policie…

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

1 of these are being actively exploited right now.

Our Newcastle team can audit your Cisco estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.