Junglewise Threat Intelligence

CVE-2026-20343: Cisco Secure FMC authentication bypass in critical API

CVE-2026-20343 · Severity: high · CVSS 7.5 · Published 2026-09-16

Executive brief

Cisco Secure Firewall Management Center (FMC) is a centralized management platform used to control and monitor firewall policies across enterprise networks. A flaw in a critical API allows unauthenticated attackers to remotely download sensitive files and consume unlimited disk space, potentially rendering the management center unresponsive and causing operational outages.

Technical details

CVE-2026-20343 is an authentication bypass vulnerability in Cisco Secure FMC Software affecting a critical API that lacks proper access controls (CWE-306). An unauthenticated, remote attacker can invoke this API repeatedly to download restricted files and exhaust disk space, triggering a denial-of-service condition. The attack requires only network connectivity to the FMC device; no authentication or user interaction is needed. A successful exploit allows file exfiltration and DoS, potentially compromising confidentiality and availability of the management infrastructure. Cisco has released software updates to address this vulnerability.

Affected products

  • Cisco Secure FMC Software

Timeline

  • 2026-09-16: disclosed

References