CVE-2026-76420
Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability
Description
A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to incorrect initialization of encryption parameters for the AJP connector at boot time. An attacker could exploit this vulnerability by sending crafted packets to the AJP connector. A successful exploit could allow the attacker to execute commands as root and gain full control over the FMC REST APIs on the affected device. Note: This vulnerability can be exploited only if the valid sftunnel connection between Cisco Secure FMC Software and Cisco Secure FTD Software is down.
In plain language
AI Act nowBusinesses running Cisco Secure Firewall Management Center should treat this as an immediate concern: a public attack is available and no fix information has been published.
Unauthenticated remote root command execution is possible through crafted Apache JServ Protocol connector traffic because encryption parameters are initialized incorrectly at boot, allowing peer-device impersonation when the sftunnel connection is down.
What to do now
- Confirm whether you run Cisco Secure Firewall Management Center and whether any sftunnel connection to Cisco Secure Firewall Threat Defense is down.
- Ask Cisco or your support provider for the published fixed version; no fixed version is available in the current advisories.
- Until Cisco provides a fix, restore and maintain sftunnel connections, restrict access to the management appliance, and investigate unexpected management API activity.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-76420 and every CVE in our database. Create a free account — no credit card required.
Create Free Account