Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability

A security flaw in Cisco Secure Firewall Management Center (FMC) software could let attackers who control certain approved hosts run any commands they want with full system rights. This problem happens because the software improperly processes certain Java data streams it receives from these hosts. Attackers can send crafted data to a specific port to exploit this. If the FMC interface isn't accessible over the public internet, the risk is lower. Cisco released updates to fix this vulnerability but no simple workaround exists.

Published 16/9/2026, 4:00:00 pmVerified 17/9/2026, 10:08:15 amRevision 1
Cisco critical network security advisory visual

In plain language

What this advisory means

A security flaw in Cisco Secure Firewall Management Center (FMC) software could let attackers who control certain approved hosts run any commands they want with full system rights. This problem happens because the software improperly processes certain Java data streams it receives from these hosts. Attackers can send crafted data to a specific port to exploit this. If the FMC interface isn't accessible over the public internet, the risk is lower. Cisco released updates to fix this vulnerability but no simple workaround exists.

Technical explanation

How the issue affects the environment

The vulnerability exists in the External Database Access feature of Cisco Secure Firewall Management Center software due to insecure deserialization of user-supplied Java byte streams from hosts permitted in the external database access list. An unauthenticated remote attacker controlling such a host can send a specially crafted serialized Java byte stream to a designated TCP port on the affected device. Exploitation allows arbitrary command execution with root privileges on the device. This elevates the attacker's rights, potentially compromising the firewall's management and security controls. The attack surface is reduced if the FMC management interface lacks public internet exposure. Cisco provided fixed software releases to remediate the issue and recommends upgrading. There are no workarounds; disabling External Database Access can mitigate exposure temporarily but might impact functionality.

Operational impact

Why teams should care

Successful exploitation could let an attacker fully control the Cisco Secure Firewall Management Center device, executing commands as root. This jeopardizes the entire firewall management infrastructure, risking unauthorized changes, network disruption, data compromise, or further lateral attacks inside the protected network. Organizations rely on the FMC for centralized firewall policy management, so this vulnerability poses a critical threat to operational security and network integrity.

Immediate action

Cisco strongly advises customers to upgrade to the fixed software releases provided in this advisory to address the vulnerability. Disabling the External Database Access feature can mitigate risk temporarily but is not a complete solution and may impair functionality. No other workarounds exist. Customers should verify their FMC management interface exposure and promptly deploy updates to eliminate the vulnerability.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

There are no direct workarounds that fully address this vulnerability. Administrators may mitigate exposure by disabling the External Database Access feature until they apply a fixed software release. However, this mitigation may negatively affect network functionality and should be evaluated carefully before implementation.

Evidence and validation checklist

  • Cisco official advisory details the vulnerability mechanism and impact.
  • Cisco confirms no known public exploitation or announcements.
  • No workarounds exist; mitigation by disabling External Database Access is stated.
  • Fixed software releases are provided by Cisco as remediation.
  • CVE-2026-20242 is assigned and documented by Cisco.

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source