Security Flaw in Cisco Secure FMC and FTD Software Affecting Device Communication
CVE-2026-20323
What is CVE-2026-20323?
A flaw exists in the sftunnel inter-device communication protocol used by Cisco Secure FMC and FTD Software, which may allow an adjacent attacker to impersonate a peer device. This vulnerability arises from inadequate management of the TLS certificate associated with the sftunnel management connection. An attacker exploiting this issue can connect to the sftunnel port using a crafted TLS certificate, potentially gaining manager-level access rights. The exploit is contingent upon either the sftunnel connection being inactive or the attacker managing to disrupt the connection long enough to initiate the attack.
Affected Version(s)
Cisco Secure Firewall Management Center (FMC) 7.0.0
Cisco Secure Firewall Management Center (FMC) 7.0.0.1
Cisco Secure Firewall Management Center (FMC) 7.0.1