ZeroHour

CVE-2026-20242

large

Unauthenticated Java Deserialization RCE in Cisco Secure Firewall Management Center

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Cisco Secure Firewall Management Center (FMC) Software contains a critical insecure deserialization flaw (CWE-502) in its External Database Access feature. An attacker who controls a host listed in the FMC's external database access list can send a crafted serialized Java byte stream to a specific TCP port on the device. Because the deserialization is insecure and the attack is unauthenticated at the protocol level, a successful exploit lets the attacker execute arbitrary commands on the appliance and elevate privileges to root. All deployments of Cisco FMC with the External Database Access feature enabled are potentially affected, though exposure is substantially reduced when the FMC management interface is not reachable from the public internet. Exploitation status: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Upgrade FMC to a fixed release per Cisco's security advisory as soon as one is published. As interim mitigation, review and restrict the external database access list to fully trusted hosts, limit which hosts can reach the affected TCP port, and ensure the FMC management interface is not exposed to the public internet. Verify configuration via the FMC admin console and monitor Cisco PSIRT for updates.

Affected
Cisco Secure Firewall Management Center (FMC) Software
Estimated exposure
large≈10,000–100,000 FMC deployments worldwide, with likely only a few thousand management interfaces internet-exposed — Cisco Secure Firewall (formerly Firepower) has a large enterprise installed base for which FMC is the central manager, but public internet scans typically show only a few thousand FMC management interfaces exposed, since most are deployed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access list. An attacker could exploit this vulnerability by sending a crafted, serialized Java byte stream to a specific TCP port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the device and elevate privileges to root. Notes: This vulnerability can be exploited only by an attacker who has control of a host in the external database access list. If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-20242, an unauthenticated deserialization flaw in Cisco Secure Firewall Management Center enabling remote code execution (CVSS 8.1).

ZDI published advisory ZDI-26-709 describing deserialization of untrusted data in Cisco Secure Firewall Management Center's CommandSinkRmi component, tracked as CVE-2026-20242 with CVSS 8.1. Remote attackers can execute arbitrary code on affected installations without authentication. The advisory does not indicate whether exploitation has been observed in the wild.