Remote Code Execution Vulnerability in Cisco Secure FMC Software
CVE-2026-20341

9.1CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20341?

A vulnerability exists in the sftunnel inter-device communication protocol of Cisco Secure FMC Software, allowing an authenticated remote attacker to exploit unsecured deserialization of untrusted data. By sending specially crafted sftunnel remote procedure calls (RPCs), the attacker can gain root privileges on the device, including its high-availability peer, provided they possess valid administrative credentials for a managed Cisco FTD device. This underscores the importance of securing communication protocols and validating incoming data to mitigate such risks.

Affected Version(s)

Cisco Secure Firewall Management Center (FMC) 7.0.0

Cisco Secure Firewall Management Center (FMC) 7.0.0.1

Cisco Secure Firewall Management Center (FMC) 7.0.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.