Directory Traversal Vulnerability in Cisco Secure Firewall Management Center Software
CVE-2026-20018
What is CVE-2026-20018?
A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center and Threat Defense Software arises from inadequate validation of directory paths during file synchronization. This weakness allows an authenticated attacker with administrative access to craft malicious directory paths, potentially resulting in unauthorized file creation or replacement on the operating system. The implications of this vulnerability can be severe, as it may enable attackers to manipulate critical system files, leading to compromises of system integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Secure Firewall Management Center (FMC) 7.0.0
Cisco Secure Firewall Management Center (FMC) 7.0.0.1
Cisco Secure Firewall Management Center (FMC) 7.0.1
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved