Cisco Security Advisory
Follow
Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability
A critical vulnerability exists in Cisco Secure Firewall Management Center (FMC) Software's External Database Access feature. This flaw allows unauthenticated, remote attackers to execute arbitrary commands as root on affected devices. The vulnerability stems from insecure deserialization of a user-supplied Java byte stream. Attackers can exploit this by sending a specially crafted byte stream to a specific TCP port on an affected device. Crucially, exploitation requires the attacker to control a host on the external database access list. If the FMC management interface lacks public internet access, the attack risk is lessened. Cisco has released software updates to fix this vulnerability. There are no workarounds available to mitigate this issue. The affected component is the External Database Access feature. The vulnerability is identified by CVE-2026-20242.