Memory Exhaustion Vulnerability in Cisco Secure FMC and FTD Software
CVE-2026-20295
What is CVE-2026-20295?
A flaw in the sftunnel communication protocol of Cisco's Secure FMC and FTD Software could enable an unauthenticated remote attacker to exhaust device memory. This vulnerability arises from improper memory resource management during the setup of sftunnel TLS connections. By sending specially crafted TLS frames during the connection setup, an attacker could potentially overload the affected device’s memory, leading to a denial of service (DoS) condition. Organizations using affected versions of Cisco Secure FMC or FTD Software should take immediate measures to secure their systems against such attacks.
Affected Version(s)
Cisco Secure Firewall Management Center (FMC) 7.0.0
Cisco Secure Firewall Management Center (FMC) 7.0.0.1
Cisco Secure Firewall Management Center (FMC) 7.0.1