Executive brief
Cisco Secure Firewall Management Center and Threat Defense Software use an inter-device communication protocol (sftunnel) to manage connections between firewall appliances. An unauthenticated attacker on the same network can bypass authentication by presenting a forged certificate, gaining root-level access to the firewall. Successful exploitation requires the sftunnel connection to be temporarily down or disrupted, allowing an attacker to assume the identity of a trusted peer device.
Technical details
This vulnerability (CVE-2026-20323) stems from improper TLS certificate validation in the sftunnel inter-device communication protocol. An unauthenticated, adjacent attacker can exploit this by connecting to the sftunnel port with a crafted TLS certificate to impersonate a peer device and register with root-level (manager role) privileges. The attack vector is adjacent network access; exploitation succeeds only when the existing sftunnel connection is down or can be disrupted. A successful exploit grants full administrative access equivalent to root on both Cisco Secure FMC and Secure FTD appliances. Cisco has released software updates to address this vulnerability; no workarounds are available.
Affected products
- Cisco Secure Firewall Management Center Multiple releases (see vendor advisory for specific versions)
- Cisco Secure Firewall Threat Defense Multiple releases (see vendor advisory for specific versions)
Timeline
- 2026-09-16: disclosed: CVE-2026-20323 published