Skip to main content

Threats Tagged 'cve-2026-20242'

View all threats tagged with 'cve-2026-20242'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-20242

Threats Tagged 'cve-2026-20242'

Click on any threat for detailed analysis and mitigation recommendations

A critical vulnerability exists in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software that allows an unauthenticated remote attacker to execute arbitrary commands as root. The flaw arises from insecure deserialization of a user-supplied Java byte stream from a host configured in the external database access list. Exploitation requires control over a host in this access list and involves sending a crafted serialized Java byte stream to a specific TCP port. The vulnerability has a CVSS score of 9.8, indicating severe impact. The attack surface is reduced if the FMC management interface is not exposed to the public internet. No patch or remediation information is currently provided.

Join the discussion

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access list. An attacker could exploit this vulnerability by sending a crafted, serialized Java byte stream to a specific TCP port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the device and elevate privileges to root. Notes: This vulnerability can be exploited only by an attacker who has control of a host in the external database access list. If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-20242
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses