Remote Command Execution Vulnerability in Cisco Secure FMC Software via AJP Connector
CVE-2026-76420
What is CVE-2026-76420?
A vulnerability exists in Cisco Secure FMC Software related to the Apache JServ Protocol (AJP) connector. This issue is due to improper initialization of encryption parameters which can lead to potential exploitation. An unauthorized remote attacker could send specifically crafted packets to the AJP connector, allowing them to impersonate a peer device. If successfully exploited, the attacker could gain root access and execute commands through the FMC REST APIs, particularly when the secure tunnel connection to Cisco Secure FTD Software is inactive. This poses significant risks to the integrity and confidentiality of the affected systems.
Affected Version(s)
Cisco Secure Firewall Management Center (FMC) 7.0.0
Cisco Secure Firewall Management Center (FMC) 7.0.0.1
Cisco Secure Firewall Management Center (FMC) 7.0.1