CVE Tools

CVE-2026-76420

Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability

Published: Sep 16, 2026Updated: Sep 17, 2026 Sources: CVE List NVDCWE-285

Description

A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to incorrect initialization of encryption parameters for the AJP connector at boot time. An attacker could exploit this vulnerability by sending crafted packets to the AJP connector. A successful exploit could allow the attacker to execute commands as root and gain full control over the FMC REST APIs on the affected device. Note: This vulnerability can be exploited only if the valid sftunnel connection between Cisco Secure FMC Software and Cisco Secure FTD Software is down.

In plain language

AI Act now

Businesses running Cisco Secure Firewall Management Center should treat this as an immediate concern: a public attack is available and no fix information has been published.

Executive summary

Unauthenticated remote root command execution is possible through crafted Apache JServ Protocol connector traffic because encryption parameters are initialized incorrectly at boot, allowing peer-device impersonation when the sftunnel connection is down.

If affected, business impact
Full management system takeoverFirewall policy tamperingNetwork access disruptionSensitive configuration exposureService outage risk

What to do now

  1. Confirm whether you run Cisco Secure Firewall Management Center and whether any sftunnel connection to Cisco Secure Firewall Threat Defense is down.
  2. Ask Cisco or your support provider for the published fixed version; no fixed version is available in the current advisories.
  3. Until Cisco provides a fix, restore and maintain sftunnel connections, restrict access to the management appliance, and investigate unexpected management API activity.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:HPR:NUI:NS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:HAttack Complexity
High
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Cisco
commercial·USaka cisco systems inc., cisco systems

Exploitability

0 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

References

1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-76420 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows