【Security Vulnerability Alert】Cisco Secure FMC has high-risk security vulnerabilities (CVE-2026-20242 and CVE-2026-20324), please confirm and apply patches as soon as possible

 
2026/10/8 ~ 2027/4/8
View Count:43

Forwarded National Information and Analysis Center for Cyber Security Cybersecurity Information Alert NISAC-200-202610-00000002

[Description]
Researchers have discovered multiple high-risk security vulnerabilities (CVE-2026-20242 and CVE-2026-20324) in Cisco Secure FMC, which are respectively classified as Insecure Deserialization and ImproperAccess Control. Please confirm and apply patches as soon as possible.
【CVE-2026-20242】 When the External Database Access feature is enabled and hosts have been configured in the access list, an unauthenticated remote attacker can send a crafted Java serialized byte stream from a host in the list to a specific TCP port, thereby executing arbitrary commands with root privileges on affected devices.
【CVE-2026-20324】 When the sftunnel protocol is enabled (enabled by default), an authenticated remote attacker can hijack an sftunnel connection or impersonate a legitimately registered sftunnel peer to send commands, write malicious files to arbitrary locations on the device, and execute arbitrary code with root privileges.

[Affected Platforms]
Cisco Secure FMC versions 7.0.0 to 7.0.9, 7.2.0 to 7.2.11, 7.3.0 to 7.3.1.2, 7.4.0 to 7.4.7, 7.6.0 to 7.6.5, 7.7.0 to 7.7.12, and 10.0.0 to 10.0.1

[Recommended Measures]
The vendor has released patches or updates for the vulnerabilities. Please refer to the official instructions for remediation. The URLs are as follows: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sftunn-codex-c3O4Jft2

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-20242
2. https://nvd.nist.gov/vuln/detail/CVE-2026-20242
3. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk
4. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sftunn-codex-c3O4Jft2
5. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP

Files
None
Top↑