H-ISAC TLP White Threat Bulletin Cisco Discloses Max Severity Vulnerability in Firewall Management Center
H-ISAC TLP White Threat Bulletin Cisco Discloses Max Severity Vulnerability in Firewall Management Center (FMC) (CVE-2025-20265)
On August 14, 2025, Cisco disclosed a critical remote code execution (RCE) vulnerability, tracked as CVE-2025-20265, affecting Cisco Secure Firewall Management Center (FMC) software.
The flaw has a CVSSv3 score of 10.0 and specifically affects Cisco Secure FMC software versions 7.0.7 and 7.7.0 if they have RADIUS authentication enabled.
Successful exploitation could allow an unauthenticated remote attacker to inject arbitrary shell commands, potentially leading to complete system compromise.
Health-ISAC provides this information to increase situational awareness, encourage users to assess their level of risk to this vulnerability, and apply the available software updates.
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: