Remote Command Execution in Cisco Secure Firewall Management Center Software
CVE-2026-20324

9.9CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

📈 Score: 775👾 Exploit Exists

What is CVE-2026-20324?

CVE-2026-20324 is a serious vulnerability found in Cisco's Secure Firewall Management Center (FMC) Software. The FMC is designed to manage and centralize security policies across multiple Cisco firewalls, playing a crucial role in network security management for organizations. This vulnerability arises from flaws in the sftunnel inter-device communication protocol, where an authenticated remote attacker could exploit incorrect permissions to execute arbitrary commands on the affected device with root privileges. Specifically, the vulnerability allows an attacker, who must already possess valid user credentials, to hijack the sftunnel communication connection or masquerade as a valid peer to write malicious files to the device's file system. Such exploits could lead to severe outcomes, including complete control over the affected system.

Potential impact of CVE-2026-20324

  1. Unauthorized System Access: The ability to execute arbitrary commands as root compromises the integrity and confidentiality of the system, granting attackers the capability to manipulate configurations and sensitive data without detection.

  2. Data Breach Risk: Exploiting the vulnerability could lead to unauthorized access to critical organizational data, resulting in potential data theft, exfiltration, or destruction, which could severely impact an organization’s operational continuity and reputation.

  3. Wider Network Compromise: Given the role of the FMC in managing multiple firewalls, a successful attack could permit lateral movement within an organization's network, allowing attackers to compromise additional devices and escalate their attack further.

Affected Version(s)

Cisco Secure Firewall Management Center (FMC) 7.0.0

Cisco Secure Firewall Management Center (FMC) 7.0.0.1

Cisco Secure Firewall Management Center (FMC) 7.0.1

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.