Executive brief
Cisco Secure Firewall Management Center (FMC) is a centralized management platform for Cisco Secure Firewall products. A vulnerability in its Apache JServ Protocol (AJP) connector allows an unauthenticated attacker to impersonate a peer device and gain root-level command execution and full control of the FMC's REST APIs, effectively taking over the management platform. This can only be exploited when the backup tunnel connection to Cisco Secure Firewall Threat Defense (FTD) devices is unavailable.
Technical details
This vulnerability stems from incorrect initialization of encryption parameters for the AJP connector at boot time in Cisco Secure FMC Software. An unauthenticated, remote attacker can exploit this by sending crafted packets to the AJP connector, allowing peer device impersonation. Successful exploitation grants the attacker root command execution and full control over FMC REST APIs. Notably, this vulnerability requires the sftunnel connection between Cisco Secure FMC and Cisco Secure FTD to be down, reducing the attack window in properly configured deployments. Cisco has released software updates to address this vulnerability, with no workarounds available.
Affected products
- Cisco Secure Firewall Management Center
Timeline
- 2026-09-16: disclosed