Junglewise Threat Intelligence

CVE-2026-20324: Cisco Secure Firewall Management Center sftunnel arbitrary file write privilege escalation

CVE-2026-20324 · Severity: critical · CVSS 9.9 · Published 2026-09-16

Executive brief

Cisco Secure Firewall Management Center (FMC) is a centralized management platform for Cisco firewalls and security appliances. A vulnerability in its sftunnel inter-device communication protocol allows authenticated attackers with valid credentials to write arbitrary files executed as root, enabling complete compromise of the management system and all connected security devices.

Technical details

A CWE-862 (Improper Authorization) vulnerability exists in the sftunnel protocol where registered sftunnel peers have incorrect file write permissions, allowing them to write arbitrary files to any location on the device. An attacker can exploit this by either hijacking an sftunnel communication connection or leveraging valid sftunnel peer status to send a malicious sftunnel command that writes a file to disk. The file is subsequently executed with root privileges, achieving arbitrary code execution. The attacker must possess valid user credentials on the affected FMC device to exploit this vulnerability. Cisco has released software patches to address this issue; no workarounds are available.

Affected products

  • Cisco Secure Firewall Management Center See Cisco advisory for affected releases

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Cisco released software updates on the same date as disclosure

References

Related threats