Remote Code Execution Vulnerability in Cisco Secure FMC Software
CVE-2026-20341
9.1CRITICAL
What is CVE-2026-20341?
A vulnerability exists in the sftunnel inter-device communication protocol of Cisco Secure FMC Software, allowing an authenticated remote attacker to exploit unsecured deserialization of untrusted data. By sending specially crafted sftunnel remote procedure calls (RPCs), the attacker can gain root privileges on the device, including its high-availability peer, provided they possess valid administrative credentials for a managed Cisco FTD device. This underscores the importance of securing communication protocols and validating incoming data to mitigate such risks.
Affected Version(s)
Cisco Secure Firewall Management Center (FMC) 7.0.0
Cisco Secure Firewall Management Center (FMC) 7.0.0.1
Cisco Secure Firewall Management Center (FMC) 7.0.1