Executive brief
Cisco Secure Firewall Management Center (FMC) contains a vulnerability in its inter-device communication protocol that allows authenticated attackers with administrative access to a managed Firepower Threat Defense device to execute arbitrary commands as root on the FMC and its high-availability peer. An attacker who compromises an FTD device with admin credentials could escalate privileges to control the entire firewall management infrastructure, leading to potential takeover of all protected networks and data.
Technical details
This vulnerability exists in the sftunnel inter-device communication protocol and is caused by insecure deserialization of untrusted data. An authenticated attacker with valid administrative credentials on a managed Cisco FTD device can send crafted sftunnel remote procedure calls (RPCs) over the management connection to exploit this flaw. The vulnerability is reachable over the network (AV:N) with low attack complexity (AC:L) and high privileges required (PR:H). A successful exploit grants root-level command execution on both the primary FMC and its high-availability peer. Cisco has released software updates to address this vulnerability and no workarounds are available.
Affected products
- Cisco Secure Firewall Management Center
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Cisco released software updates