Skip to content

CVE-2026-20341 CVE-2026-20340 CVE-2026-20344 CVE-2026-20342 CVE-2026-20343

Cisco Secure Firewall Management Center flaws allow root command execution, SQL injection and DoS (CVE-2026-20340 to CVE-2026-20344)

Critical 9.1 Vendor: Cisco Published

Cisco disclosed five Secure Firewall Management Center vulnerabilities: root command execution, SQL injection, arbitrary file download and an unauthenticated API denial-of-service. No workarounds exist. Review Cisco's advisory, restrict management access, and apply the fixed software.

What happened

Cisco's advisory bundles five vulnerabilities in Cisco Secure Firewall Management Center (FMC). CVE-2026-20341 allows an authenticated remote attacker with valid administrative credentials on a managed Cisco FTD device to send crafted sftunnel remote procedure calls and gain root privileges on the FMC and its high-availability peer. CVE-2026-20340 allows an attacker with at least a Security Analyst (read-only) account to save a crafted HTTP payload and later execute it as root. CVE-2026-20344 is a SQL injection in the web management interface; with Security Approver, Access Admin or Network Admin access, an attacker can obtain database data and session credentials of an authenticated Administrator, then act with administrative privileges. CVE-2026-20342 lets a Security Analyst download arbitrary files through a file download API.

CVE-2026-20343 is unauthenticated. A critical API lacks authentication, and an attacker can repeatedly invoke it to download sensitive files that should be restricted and consume disk space until the device becomes unresponsive. All five issues are reachable over the network and require no user interaction. Cisco PSIRT states it is not aware of any public announcements or malicious use, and none of the CVEs is listed in CISA KEV.

Who is affected

Cisco Secure Firewall Management Center is the central management platform for Cisco Secure Firewall and Firepower Threat Defense deployments. It usually sits in an administrative segment and manages firewall policies and devices. CVE-2026-20340, CVE-2026-20341, CVE-2026-20342 and CVE-2026-20344 affect versions 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.2.0, 7.0.2.1 and 7.0.3. CVE-2026-20343 affects versions 7.3.0, 7.3.1, 7.3.1.1, 7.4.0, 7.4.1, 7.4.1.1, 7.3.1.2 and 7.6.0.

What to do now

  1. Confirm whether your FMC runs one of the affected versions listed above, and note which CVE applies to your version.
  2. Consult the Cisco advisory and apply the fixed software for your release. Cisco states that no workarounds address these vulnerabilities.
  3. Until the update is applied, restrict access to the FMC web management interface and the sftunnel management connection to trusted administrative hosts only.
  4. Review local accounts and roles on FMC and managed FTD devices. Remove unused or over-privileged accounts, because several of these vulnerabilities require authenticated access.
  5. Monitor FMC disk utilisation and API request volume for unexplained growth, particularly because one of the issues is an unauthenticated API.

How to detect it

Check whether the FMC web management interface or the sftunnel management connection is reachable from anything other than the administrative network. Because one vulnerability is an unauthenticated API that consumes disk, monitor FMC disk usage and API request volume for unexplained growth or repeated invocation.

Beyond the patch

These vulnerabilities sit in the management plane, not the data plane, so a compromised FMC can affect firewall policy across the estate. Deserialisation, SQL injection and missing authentication on a management interface are exactly what Implementation & Assessment Services is designed to test and harden before an advisory forces the issue. Because FMC is vendor software at the centre of that estate, track the fix through Supply Chain Defense & Third-Party Risk so the upgrade is assessed, planned and verified.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-20341
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20340
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20344
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20342
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20343
Cisco Secure Firewall Management Center (FMC)
7.3.0
7.3.1
7.3.1.1
7.4.0
7.4.1
7.4.1.1
7.3.1.2
7.6.0
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.