ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 7 sources: “Cisco September 2026 Firewall Hardening Release Fixes Multiple ASA/FTD/FMC Flaws, Two Actively Exploited; ZDI Details FMC Deserialization RCE CVE-2026-20242” — merged summary and timeline →

ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability

AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-20242, an unauthenticated deserialization flaw in Cisco Secure Firewall Management Center enabling remote code execution (CVSS 8.1).

ZDI published advisory ZDI-26-709 describing deserialization of untrusted data in Cisco Secure Firewall Management Center's CommandSinkRmi component, tracked as CVE-2026-20242 with CVSS 8.1. Remote attackers can execute arbitrary code on affected installations without authentication. The advisory does not indicate whether exploitation has been observed in the wild.

  • Deserialization of untrusted data in Cisco FMC CommandSinkRmi, CVE-2026-20242
  • Unauthenticated remote code execution, CVSS 8.1
  • Affects Cisco Secure Firewall Management Center security appliance

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20242
Unauthenticated Java Deserialization RCE in Cisco Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC) Software contains a critical insecure deserialization flaw (CWE-502) in its External Database Access feature. An attacker who controls a host listed in the FMC's external database access list can send a crafted serialized Java byte stream to a specific TCP port on the device. Because the deserialization is insecure and the attack is unauthenticated at the protocol level, a successful exploit lets the attacker execute arbitrary commands on the appliance and elevate privileges to root. All deployments of Cisco FMC with the External Database Access feature enabled are potentially affected, though exposure is substantially reduced when the FMC management interface is not reachable from the public internet. Exploitation status: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

Do: Upgrade FMC to a fixed release per Cisco's security advisory as soon as one is published. As interim mitigation, review and restrict the external database access list to fully trusted hosts, limit which hosts can reach the affected TCP port, and ensure the FMC management interface is not exposed to the public internet. Verify configuration via the FMC admin console and monitor Cisco PSIRT for updates.

9.8
  • Cisco Secure Firewall Management Center (FMC) Software
large≈10,000–100,000 FMC deployments worldwide, with likely only a few thousand management interfaces internet-exposed
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-20242.

This source does not provide full text. Read it at zerodayinitiative.com.