Junglewise Threat Intelligence

CVE-2026-20323: Cisco Secure FMC and FTD sftunnel authentication bypass

CVE-2026-20323 · Severity: high · CVSS 8.3 · Published 2026-09-16

Executive brief

Cisco Secure Firewall Management Center and Threat Defense Software use an inter-device communication protocol (sftunnel) to manage connections between firewall appliances. An unauthenticated attacker on the same network can bypass authentication by presenting a forged certificate, gaining root-level access to the firewall. Successful exploitation requires the sftunnel connection to be temporarily down or disrupted, allowing an attacker to assume the identity of a trusted peer device.

Technical details

This vulnerability (CVE-2026-20323) stems from improper TLS certificate validation in the sftunnel inter-device communication protocol. An unauthenticated, adjacent attacker can exploit this by connecting to the sftunnel port with a crafted TLS certificate to impersonate a peer device and register with root-level (manager role) privileges. The attack vector is adjacent network access; exploitation succeeds only when the existing sftunnel connection is down or can be disrupted. A successful exploit grants full administrative access equivalent to root on both Cisco Secure FMC and Secure FTD appliances. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco Secure Firewall Management Center Multiple releases (see vendor advisory for specific versions)
  • Cisco Secure Firewall Threat Defense Multiple releases (see vendor advisory for specific versions)

Timeline

  • 2026-09-16: disclosed: CVE-2026-20323 published

References

Related threats