Memory Exhaustion Vulnerability in Cisco Secure FMC and FTD Software
CVE-2026-20295

8.6HIGH

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-20295?

A flaw in the sftunnel communication protocol of Cisco's Secure FMC and FTD Software could enable an unauthenticated remote attacker to exhaust device memory. This vulnerability arises from improper memory resource management during the setup of sftunnel TLS connections. By sending specially crafted TLS frames during the connection setup, an attacker could potentially overload the affected device’s memory, leading to a denial of service (DoS) condition. Organizations using affected versions of Cisco Secure FMC or FTD Software should take immediate measures to secure their systems against such attacks.

Affected Version(s)

Cisco Secure Firewall Management Center (FMC) 7.0.0

Cisco Secure Firewall Management Center (FMC) 7.0.0.1

Cisco Secure Firewall Management Center (FMC) 7.0.1

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.