CVE-2026-20242
Cisco Secure Firewall Management Center Java deserialization allows remote code execution as root (CVE-2026-20242)
Cisco Secure Firewall Management Center has a critical Java deserialization flaw in External Database Access. An unauthenticated attacker who controls a configured database host can run commands as root. Cisco has published fixes; disable External Database Access until you apply the fixed release.
What happened
A flaw in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software allows an unauthenticated, remote attacker to execute arbitrary commands as root. The issue is insecure deserialisation: the feature accepts a user-supplied Java byte stream from a host configured in the external database access list, and a crafted serialised Java byte stream sent to a specific TCP port can be deserialised in a way that leads to command execution and root privilege escalation.
The key exposure condition is that the attacker must control a host named in the FMC's external database access list. If the FMC management interface is not reachable from the public internet, Cisco notes the attack surface is reduced. Cisco PSIRT states it is not aware of any public announcements or malicious use of this vulnerability.
Who is affected
Cisco Secure Firewall Management Center (FMC) Software is affected. The releases listed in the advisory are: 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3 and 7.2.0. The practical exposure is limited to deployments where External Database Access is enabled and at least one host is configured in the external database access list.
What to do now
- Confirm whether your FMC release and feature configuration are affected: check the version against the list above and determine whether External Database Access is in use.
- Apply the fixed software for your release, as identified in Cisco's advisory.
- If you cannot patch immediately, use Cisco's mitigation: disable External Database Access until a fixed release is deployed. Cisco notes this has been proven successful in a test environment, but you should evaluate it for your own environment; it may affect functionality.
- Reduce exposure to the management interface. The attack surface is smaller if the FMC management interface has no public internet access.
How to detect it
The Cisco advisory does not provide indicators of compromise. Two practical checks follow from the vulnerability: confirm externally that the FMC management interface and External Database Access listener are not reachable from unintended networks; and watch internally for unexpected root-level command execution on FMC, since successful exploitation runs commands as root.
Beyond the patch
Beyond applying the fix, this is a reminder that a management plane should be treated as a crown-jewels asset. A root shell on FMC can undermine the firewall policies the rest of the estate relies on. Virtual CISO Services can help you map and reduce internet-exposed management interfaces, and Managed Detection & Response can monitor for the root-level command execution that this kind of post-exploitation leaves behind.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |