Junglewise Threat Intelligence

CVE-2026-20341: Cisco Secure FMC Software unsecured deserialization in sftunnel

CVE-2026-20341 · Severity: critical · CVSS 9.1 · Published 2026-09-16

Executive brief

Cisco Secure Firewall Management Center (FMC) contains a vulnerability in its inter-device communication protocol that allows authenticated attackers with administrative access to a managed Firepower Threat Defense device to execute arbitrary commands as root on the FMC and its high-availability peer. An attacker who compromises an FTD device with admin credentials could escalate privileges to control the entire firewall management infrastructure, leading to potential takeover of all protected networks and data.

Technical details

This vulnerability exists in the sftunnel inter-device communication protocol and is caused by insecure deserialization of untrusted data. An authenticated attacker with valid administrative credentials on a managed Cisco FTD device can send crafted sftunnel remote procedure calls (RPCs) over the management connection to exploit this flaw. The vulnerability is reachable over the network (AV:N) with low attack complexity (AC:L) and high privileges required (PR:H). A successful exploit grants root-level command execution on both the primary FMC and its high-availability peer. Cisco has released software updates to address this vulnerability and no workarounds are available.

Affected products

  • Cisco Secure Firewall Management Center

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Cisco released software updates

References

Related threats