Skip to content
ThreatCluster

Cisco Secure Firewall Management Center RCE Vulnerability Disclosed

First seen 16 Sep 2026, 22:50 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 00:21 UTC
  • Critical RCE vulnerability in Cisco FMC Software affecting external database access.
  • Attackers can execute arbitrary commands as root if they control a host in the access list.
  • Cisco has issued patches; no workarounds are available.

A critical vulnerability has been identified in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software, allowing unauthenticated remote attackers to execute arbitrary commands as root. This vulnerability arises from insecure deserialization of a user-supplied Java byte stream from hosts in the external database access list. Attackers can exploit this by sending a crafted Java byte stream to a specific TCP port of the affected device. Successful exploitation could lead to full system compromise. Cisco has released software updates to address this issue, but no workarounds are available. The attack surface is reduced if the FMC management interface is not publicly accessible. This advisory is part of a broader set of advisories released on September 16, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
Vulnerability disclosed
Cisco announced a critical RCE vulnerability in FMC Software, affecting devices with external database access.
Sec.Cloudapps.Cisco
2026-09-16
Software updates released
Cisco released updates to mitigate the vulnerability, urging users to apply them immediately.
Sec.Cloudapps.Cisco

More articles in this cluster (2)