Junglewise Threat Intelligence

CVE-2026-76420: Cisco Secure FMC AJP connector peer impersonation

CVE-2026-76420 · Severity: critical · CVSS 9 · Published 2026-09-16

Executive brief

Cisco Secure Firewall Management Center (FMC) is a centralized management platform for Cisco Secure Firewall products. A vulnerability in its Apache JServ Protocol (AJP) connector allows an unauthenticated attacker to impersonate a peer device and gain root-level command execution and full control of the FMC's REST APIs, effectively taking over the management platform. This can only be exploited when the backup tunnel connection to Cisco Secure Firewall Threat Defense (FTD) devices is unavailable.

Technical details

This vulnerability stems from incorrect initialization of encryption parameters for the AJP connector at boot time in Cisco Secure FMC Software. An unauthenticated, remote attacker can exploit this by sending crafted packets to the AJP connector, allowing peer device impersonation. Successful exploitation grants the attacker root command execution and full control over FMC REST APIs. Notably, this vulnerability requires the sftunnel connection between Cisco Secure FMC and Cisco Secure FTD to be down, reducing the attack window in properly configured deployments. Cisco has released software updates to address this vulnerability, with no workarounds available.

Affected products

  • Cisco Secure Firewall Management Center

Timeline

  • 2026-09-16: disclosed

References

Related threats