Description
A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device.

This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access list. An attacker could exploit this vulnerability by sending a crafted, serialized Java byte stream to a specific TCP port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the device and elevate privileges to root.
Notes:

This vulnerability can be exploited only by an attacker who has control of a host in the external database access list.
If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A remote attacker can exploit the External Database Access feature of Cisco Secure Firewall Management Center (FMC) by sending a crafted, serialized Java byte stream to a listening TCP port. The deserialization flaw, identified as CWE‑502, allows arbitrary command execution with root privileges on the affected device, enabling a complete takeover of the system.

Affected Systems

Cisco Secure Firewall Management Center (FMC) software is affected. No specific software versions are listed in the available data, so any installed instance of this product remains potentially vulnerable until an official fix is applied. The vulnerability is only applicable to FMC deployments that have external database access configured.

Risk and Exploitability

The CVSS score of 9.8 indicates severe risk; however, the EPSS score of less than 1% suggests that exploitation attempts are currently very rare. The flaw is not listed in the CISA KEV catalog. Successful exploitation requires the attacker to control a host that is on the FMC’s external database access list, meaning the attack surface is constrained to environments where the FMC is reachable from that host. If the management interface is not exposed to the public internet, the available attack surface diminishes further. The vulnerability is unauthenticated, so any host in the external database list can be used to launch the exploit.

Generated by OpenCVE AI on September 17, 2026 at 20:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Cisco’s latest security update that patches the insecure deserialization flaw in FMC.
  • Restrict or remove any untrusted hosts from the external database access list for FMC.
  • Block or limit the specific TCP port used for external database access through firewall rules or by using network segmentation to isolate the FMC management interface from publicly reachable networks.

Generated by OpenCVE AI on September 17, 2026 at 20:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Management Center
Vendors & Products Cisco
Cisco secure Firewall Management Center

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as&nbsp;root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access list. An attacker could exploit this vulnerability by sending a crafted, serialized Java byte stream to a specific TCP port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the device and elevate privileges to root. Notes: This vulnerability can be exploited only by an attacker who has control of a host in the external database access list. If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
Title Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Secure Firewall Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T03:55:57.449Z

Reserved: 2025-10-08T11:59:15.400Z

Link: CVE-2026-20242

cve-icon Vulnrichment

Updated: 2026-09-17T14:55:30.453Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:22.697

Modified: 2026-09-18T04:17:34.083

Link: CVE-2026-20242

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:25Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data