THREAT OPS › Threat News › Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability
Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability
<p>A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as <em>root </em>on an affected device.</p> <p>This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access
Indicators of compromise
- CVE-2026-20242cve