CVE-2026-20324
Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability
Description
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerability by hijacking the sftunnel communication connection or being a valid registered sftunnel peer and sending an sftunnel command to write a malicious file to the disk of an affected device. A successful exploit could allow the attacker to write a file to the device that is executed with root privileges. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
In plain language
AI Act nowCisco Secure Firewall Management Center (FMC) has a critical flaw that lets a logged-in attacker take full control of the device; affected versions are not yet known.
Authenticated remote root code execution in Cisco Secure Firewall Management Center (FMC) through incorrect file-write permissions in the sftunnel inter-device communication protocol.
What to do now
- Check whether you run Cisco Secure Firewall Management Center (FMC) and identify its installed software version.
- Restrict FMC management access to trusted administrators and networks while you review exposure.
- No vendor fixed version or patch information is currently available; ask Cisco or your support provider for the applicable update and deployment timeline.
- Review administrator accounts and remove or reset access that is no longer needed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20324 and every CVE in our database. Create a free account — no credit card required.
Create Free Account