Remote Command Execution Vulnerability in Cisco Secure FMC Software via AJP Connector
CVE-2026-76420

9CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-76420?

A vulnerability exists in Cisco Secure FMC Software related to the Apache JServ Protocol (AJP) connector. This issue is due to improper initialization of encryption parameters which can lead to potential exploitation. An unauthorized remote attacker could send specifically crafted packets to the AJP connector, allowing them to impersonate a peer device. If successfully exploited, the attacker could gain root access and execute commands through the FMC REST APIs, particularly when the secure tunnel connection to Cisco Secure FTD Software is inactive. This poses significant risks to the integrity and confidentiality of the affected systems.

Affected Version(s)

Cisco Secure Firewall Management Center (FMC) 7.0.0

Cisco Secure Firewall Management Center (FMC) 7.0.0.1

Cisco Secure Firewall Management Center (FMC) 7.0.1

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.