Junglewise Threat Intelligence

CVE-2026-20044: Cisco Secure Firewall Management Center command injection in lockdown mode

CVE-2026-20044 · Severity: medium · CVSS 6 · Published 2026-03-04

Vendors: Cisco.

Executive brief

Cisco Secure Firewall Management Center (FMC) is a centralized management platform for Cisco firewalls and security appliances. When lockdown mode is enabled—a hardening feature designed to restrict administrative capabilities—a flaw in how remediation modules are restricted allows authenticated administrators to bypass these protections and execute arbitrary commands with root privileges. This undermines the security hardening posture organizations rely on to reduce the attack surface of their management infrastructure.

Technical details

The vulnerability is a command injection flaw (CWE-269: improper restrictions on the input leading to command injection) in the lockdown mechanism of Cisco Secure FMC Software. The root cause is insufficient input validation and restrictions on remediation modules when the system is operating in lockdown mode. An authenticated attacker with valid administrative credentials can send crafted input to the system CLI to inject arbitrary commands that execute as root, even when lockdown mode is intended to restrict such actions. The attack is local (CLI-based) and does not require user interaction beyond CLI command submission. Cisco has released software updates to address this issue; no workarounds are available. The vulnerability affects Cisco Secure FMC Software only when lockdown mode is explicitly enabled (disabled by default).

Affected products

  • Cisco Secure Firewall Management Center (FMC) Software

Timeline

  • 2026-03-04: disclosed

References