ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-20242, an unauthenticated deserialization flaw in Cisco Secure Firewall Management Center enabling remote code execution (CVSS 8.1).
ZDI published advisory ZDI-26-709 describing deserialization of untrusted data in Cisco Secure Firewall Management Center's CommandSinkRmi component, tracked as CVE-2026-20242 with CVSS 8.1. Remote attackers can execute arbitrary code on affected installations without authentication. The advisory does not indicate whether exploitation has been observed in the wild.