Posting Date: 2026/10/05
【Vulnerability Alert】High-Risk Security Vulnerabilities in Cisco Secure FMC (CVE-2026-20242 and CVE-2026-20324), Please Verify and Patch Promptly
- Subject:【Vulnerability Alert】High-Risk Security Vulnerabilities in Cisco Secure FMC (CVE-2026-20242 and CVE-2026-20324), Please Verify and Patch Promptly
- Description:
- Forwarded NISAC Cybersecurity Message Alert NISAC-200-202610-00000002
- Researchers have discovered multiple high-risk security vulnerabilities in Cisco Secure FMC (CVE-2026-20242 and CVE-2026-20324), namely insecure deserialization and improper access control. Please verify and patch promptly.
- 【CVE-2026-20242】 When the External Database Access feature is enabled and hosts are configured in the access list, an unauthenticated remote attacker may send a specially crafted Java serialized byte stream from a host in the list to a specific TCP port, executing arbitrary commands on affected devices with root privileges.
- 【CVE-2026-20324】 When the sftunnel protocol is enabled (enabled by default), an authenticated remote attacker may hijack the sftunnel connection or impersonate a legitimately registered sftunnel peer to send commands, write malicious files to arbitrary locations on the device, and execute arbitrary code with root privileges.
- Affected Platforms:
- Cisco Secure FMC versions 7.0.0 to 7.0.9, 7.2.0 to 7.2.11, 7.3.0 to 7.3.1.2, 7.4.0 to 7.4.7, 7.6.0 to 7.6.5, 7.7.0 to 7.7.12 and 10.0.0 to 10.0.1
- Recommended Actions:
- The vendor has released a patch or update for the vulnerability, please refer to the vendor's instructions for remediation; URL is as follows: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk
- References:
Computer and Communication Center
Network System Division