ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-20242, an unauthenticated deserialization flaw in Cisco Secure Firewall Management Center enabling remote code execution (CVSS 8.1).
ZDI published advisory ZDI-26-709 describing deserialization of untrusted data in Cisco Secure Firewall Management Center's CommandSinkRmi component, tracked as CVE-2026-20242 with CVSS 8.1. Remote attackers can execute arbitrary code on affected installations without authentication. The advisory does not indicate whether exploitation has been observed in the wild.
- Deserialization of untrusted data in Cisco FMC CommandSinkRmi, CVE-2026-20242
- Unauthenticated remote code execution, CVSS 8.1
- Affects Cisco Secure Firewall Management Center security appliance
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20242 | Unauthenticated Java Deserialization RCE in Cisco Secure Firewall Management Center Cisco Secure Firewall Management Center (FMC) Software contains a critical insecure deserialization flaw (CWE-502) in its External Database Access feature. An attacker who controls a host listed in the FMC's external database access list can send a crafted serialized Java byte stream to a specific TCP port on the device. Because the deserialization is insecure and the attack is unauthenticated at the protocol level, a successful exploit lets the attacker execute arbitrary commands on the appliance and elevate privileges to root. All deployments of Cisco FMC with the External Database Access feature enabled are potentially affected, though exposure is substantially reduced when the FMC management interface is not reachable from the public internet. Exploitation status: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known. Do: Upgrade FMC to a fixed release per Cisco's security advisory as soon as one is published. As interim mitigation, review and restrict the external database access list to fully trusted hosts, limit which hosts can reach the affected TCP port, and ensure the FMC management interface is not exposed to the public internet. Verify configuration via the FMC admin console and monitor Cisco PSIRT for updates. | 9.8 | — |
| large≈10,000–100,000 FMC deployments worldwide, with likely only a few thousand management interfaces internet-exposed |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-20242.
This source does not provide full text. Read it at zerodayinitiative.com.