Remote Command Execution in Cisco Secure Firewall Management Center Software
CVE-2026-20242
What is CVE-2026-20242?
A security vulnerability exists in the External Database Access feature of Cisco Secure Firewall Management Center Software, which could allow an unauthenticated remote attacker to execute arbitrary commands with root privileges on affected devices. This issue arises from the insecure deserialization of a user-supplied Java byte stream from hosts in the external database access configuration. An attacker with control over such a host can exploit this vulnerability by sending a maliciously crafted Java byte stream to the affected device's TCP port, thereby executing arbitrary commands and potentially escalating their privileges.
Affected Version(s)
Cisco Secure Firewall Management Center (FMC) 7.0.0
Cisco Secure Firewall Management Center (FMC) 7.0.0.1
Cisco Secure Firewall Management Center (FMC) 7.0.1