CVE-2026-20324

9.9

Cisco · Secure Firewall Management Center (FMC)

A flaw in the sftunnel protocol of Cisco Secure Firewall Management Center allows an authenticated remote attacker to write arbitrary files and execute commands as root.

Executive summary

A critical vulnerability in Cisco Secure Firewall Management Center allows authenticated attackers to achieve root-level remote code execution.

Vulnerability

This vulnerability, categorized as CWE-862, stems from improper authorization within the sftunnel inter-device communication protocol. An attacker with valid user credentials can hijack a communication channel or act as a registered peer to write malicious files to the device, which are subsequently executed with root privileges.

Business impact

The ability to execute arbitrary commands with root privileges on a management appliance represents a total compromise of the security infrastructure. As the FMC manages firewall policies and network traffic, an attacker could disable security controls, intercept sensitive data, or pivot deeper into the corporate network. With a CVSS score of 9.9, this vulnerability poses an extreme risk to organizational integrity and operational continuity.

Remediation

Immediate Action: Review the official Cisco security advisory for the latest software updates and apply the recommended patches to all affected FMC instances immediately.

Proactive Monitoring: Audit device logs for anomalous sftunnel connection activity or unauthorized file creation attempts within the system directories.

Compensating Controls: Restrict network access to the management interface to trusted administrative subnets only, and enforce strict peer authentication for all devices communicating with the FMC.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of this vulnerability and the potential for full system takeover, administrators should treat this as a high-priority remediation task. Ensure that all Cisco Secure Firewall Management Center instances are patched to the latest vendor-specified version as soon as the firmware becomes available to prevent potential exploitation of this authorization flaw.

More Cisco CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources