CVE Tools

CVE-2026-20324

Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability

Published: Sep 16, 2026Updated: Sep 18, 2026 Sources: CVE List NVDCWE-862

Description

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerability by hijacking the sftunnel communication connection or being a valid registered sftunnel peer and sending an sftunnel command to write a malicious file to the disk of an affected device. A successful exploit could allow the attacker to write a file to the device that is executed with root privileges. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.

In plain language

AI Act now

Cisco Secure Firewall Management Center (FMC) has a critical flaw that lets a logged-in attacker take full control of the device; affected versions are not yet known.

Executive summary

Authenticated remote root code execution in Cisco Secure Firewall Management Center (FMC) through incorrect file-write permissions in the sftunnel inter-device communication protocol.

If affected, business impact
Full firewall-management takeoverNetwork security policy changesSensitive network data exposureService disruption

What to do now

  1. Check whether you run Cisco Secure Firewall Management Center (FMC) and identify its installed software version.
  2. Restrict FMC management access to trusted administrators and networks while you review exposure.
  3. No vendor fixed version or patch information is currently available; ask Cisco or your support provider for the applicable update and deployment timeline.
  4. Review administrator accounts and remove or reset access that is no longer needed.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Cisco
commercial·USaka cisco systems inc., cisco systems

Exploitability

0 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
View detailed technique mapping

References

1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-20324 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows