Forwarded NISAC Cybersecurity Message Alert NISAC-200-202610-00000002
Researchers have discovered multiple high-risk security vulnerabilities in Cisco Secure FMC (CVE-2026-20242 and CVE-2026-20324), namely insecure deserialization and improper access control. Please verify and patch promptly.
【CVE-2026-20242】 When the External Database Access feature is enabled and hosts are configured in the access list, an unauthenticated remote attacker may send a specially crafted Java serialized byte stream from a host in the list to a specific TCP port, executing arbitrary commands on affected devices with root privileges.
【CVE-2026-20324】 When the sftunnel protocol is enabled (enabled by default), an authenticated remote attacker may hijack the sftunnel connection or impersonate a legitimately registered sftunnel peer to send commands, write malicious files to arbitrary locations on the device, and execute arbitrary code with root privileges.