Executive brief
Cisco Secure Firewall Management Center is a central management platform for enterprise firewalls. A flaw in its External Database Access feature allows an attacker with network access to a database host on the allowlist to send a malicious serialized Java object, achieving remote code execution with root privileges. This can lead to complete compromise of the firewall management infrastructure.
Technical details
The vulnerability is an insecure Java deserialization flaw (CWE-502) in the External Database Access feature of Cisco Secure Firewall Management Center. An unauthenticated remote attacker who controls a host configured in the external database access list can exploit this by sending a crafted serialized Java byte stream to a specific TCP port. The vulnerability allows arbitrary command execution with root privileges. Cisco has released software updates to address this issue; no workarounds are available, though disabling External Database Access mitigates the risk until patching.
Affected products
- Cisco Secure Firewall Management Center multiple versions affected; see Cisco Software Checker for specific release information
Timeline
- 2026-09-16: disclosed: CVE-2026-20242 published by Cisco