CVE Tools

CVE-2026-20344

Cisco Secure Firewall Management Center Software SQL Injection Vulnerability

Published: Sep 16, 2026Updated: Sep 18, 2026 Sources: CVE List NVDCWE-89

Description

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have a valid account on the device with the role of Security Approver, Access Admin, or Network Admin. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain any data from the database, obtain the session credentials of an authenticated Administrator, and take actions with administrative privileges on the affected device.

In plain language

AI Act now

A serious flaw in Cisco Secure Firewall Management Center lets a privileged user take over the management system; small businesses using it should act now.

Executive summary

Authenticated SQL injection in the Cisco Secure Firewall Management Center web management interface allows Security Approver, Access Admin, or Network Admin users to extract database data, hijack an Administrator session, and perform administrative actions.

If affected, business impact
Firewall management takeoverAdministrator session theftSecurity settings changedSensitive database data exposureNetwork protection disruption

What to do now

  1. Check whether you run Cisco Secure Firewall Management Center and identify everyone assigned Security Approver, Access Admin, or Network Admin roles.
  2. No fixed version has been published; ask Cisco or your support provider for the vendor-approved remediation and release plan for CVE-2026-20344.
  3. Immediately remove unnecessary privileged accounts, require multi-factor authentication where available, and restrict management-interface access to trusted administrator networks.
  4. Review recent administrator logins, role changes, configuration changes, and new accounts for unexpected activity.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Cisco
commercial·USaka cisco systems inc., cisco systems

Exploitability

0 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Initial Access
View detailed technique mapping

References

1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-20344 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows