Unauthenticated Remote Access Vulnerability in Cisco Secure FMC Software
CVE-2026-20343

7.5HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20343?

A critical vulnerability in the Cisco Secure FMC Software's API enables unauthenticated remote attackers to exploit the system. Due to inadequate authentication measures, an attacker can repeatedly call the API, resulting in the potential download of sensitive files that should be protected. Moreover, this attack can lead to excessive consumption of disk space, which may render the device unresponsive and create a Denial of Service (DoS) condition. Organizations using Cisco Secure FMC Software should seek remediation to mitigate this security flaw.

Affected Version(s)

Cisco Secure Firewall Management Center (FMC) 7.3.0

Cisco Secure Firewall Management Center (FMC) 7.3.1

Cisco Secure Firewall Management Center (FMC) 7.3.1.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.