CVE-2026-20242: pre-auth remote code execution in Cisco Cisco Secure Firewall Management Center (FMC)

An unauthenticated remote attacker can execute arbitrary commands as root on Cisco Secure Firewall Management Center (FMC), tracked as CVE-2026-20242. The flaw is insecure deserialization in the External Database Access feature and affects multiple 7.x releases (examples in vendor advisory include 7.0.0 through 7.2.0.1). Exploitation requires network access to the FMC's specific TCP service and control of a host that appears in the FMC external database access list.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00639
CWE
CWE-502
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a high-impact remote root execution with no vendor patch available; immediately reduce exposure by removing untrusted hosts from the external database access list and blocking access to the affected TCP port from untrusted networks.

What is CVE-2026-20242?

An unauthenticated remote attacker can execute arbitrary commands as root on Cisco Secure Firewall Management Center (FMC), tracked as CVE-2026-20242. The flaw is insecure deserialization in the External Database Access feature and affects multiple 7.x releases (examples in vendor advisory include 7.0.0 through 7.2.0.1). Exploitation requires network access to the FMC's specific TCP service and control of a host that appears in the FMC external database access list. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Cisco Cisco Secure Firewall Management Center (FMC) are affected?

BRANCHAFFECTEDFIXED
7.x7.0.0
7.x7.0.0.1
7.x7.0.1
7.x7.0.1.1
7.x7.0.2
7.x7.2.0
7.x7.0.2.1
7.x7.0.3
7.x7.2.0.1
7.x7.0.4

Is CVE-2026-20242 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-20242

  1. Remove any untrusted systems from the FMC external database access list.
  2. Block the FMC external database TCP port at network edge and between management and untrusted networks.
  3. Isolate the FMC management interface from the public internet and limit access to trusted admin networks.
  4. Follow Cisco's guidance and monitor FMC logs and alerts; apply vendor patches as soon as they are released.

Frequently asked questions

Is CVE-2026-20242 being actively exploited?

There are no public reports of exploitation of CVE-2026-20242 as of 2026-09-30.

Which Cisco Secure Firewall Management Center versions are affected by CVE-2026-20242?

Cisco lists multiple 7.x releases as affected; examples in the advisory include 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.2.0, 7.0.2.1, 7.0.3, 7.2.0.1, and 7.0.4.

Is there a patch for CVE-2026-20242?

No—there is no patch available according to the facts provided; follow mitigations from the vendor until a fixed release is published.

Does CVE-2026-20242 require authentication?

No authentication is required to trigger the vulnerability, but exploitation requires control of a host that is listed in the FMC external database access list and network access to the specific TCP port.

References