CVE-2026-20295 CVE-2026-20323
Cisco Secure Firewall sftunnel vulnerabilities allow denial of service and authentication bypass (CVE-2026-20295, CVE-2026-20323)
Cisco Secure Firewall Management Center and Threat Defense software have two high-severity sftunnel vulnerabilities: remote memory exhaustion denial of service (CVE-2026-20295) and adjacent authentication bypass to root (CVE-2026-20323). Fixes are available; no workarounds.
What happened
Cisco Secure Firewall Management Center (FMC) and Secure Firewall Threat Defense (FTD) software use the sftunnel protocol for inter-device communication, and two separate vulnerabilities affect it.
CVE-2026-20295 allows an unauthenticated, remote attacker to exhaust an affected device's memory by sending crafted sftunnel TLS frames during connection setup. Successful exploitation can lead to a denial-of-service condition. CVE-2026-20323 allows an unauthenticated, adjacent attacker to impersonate a peer device using a crafted TLS certificate and gain access at the manager role, which Cisco describes as equivalent to root.
The authentication bypass requires the sftunnel connection to be down, or to be disrupted for long enough, before the attacker can execute it. Cisco PSIRT states it is not aware of any public announcements or malicious use of the vulnerabilities described in this advisory, and they have not been publicly disclosed.
Who is affected
Both CVEs affect the same releases of Cisco Secure FMC Software and Cisco Secure FTD Software: 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3 and 7.2.0. These products typically operate as perimeter firewalls and central security managers, so affected deployments are usually found at network edges, in data centres, and in managed security service environments. If an FMC or FTD device is running one of these releases, review both CVEs together.
What to do now
- Identify all FMC and FTD devices running the affected releases listed above.
- Apply the Cisco fixed release. Cisco has made fixes available, but this advisory does not list the fixed version numbers; obtain the correct target release from the Cisco security advisory.
- Cisco states there are no workarounds for these vulnerabilities. Until patching is complete, restrict access to sftunnel and inter-device management interfaces to trusted administrative and peer networks only, and monitor those interfaces for unexpected TLS connection attempts or certificate changes.
- Recheck the Cisco advisory before scheduling the upgrade in case Cisco updates its fixed-release information.
How to detect it
For CVE-2026-20295, monitor FMC and FTD devices for abnormal memory consumption or unexplained denial-of-service conditions. For CVE-2026-20323, monitor sftunnel connections for unexpected drops or reconnects, and review for anomalous TLS certificate attempts from peer devices; Cisco notes the attack can succeed only if the sftunnel connection is down or can be disrupted long enough to execute the peer impersonation.
Beyond the patch
These vulnerabilities sit on management and inter-device paths that are meant to be trusted, and one of them is reachable over the network without credentials. That makes exposure control as important as the patch itself. Our Virtual CISO Services can help confirm which management and sftunnel interfaces are reachable from untrusted segments, and Supply Chain Defense & Third-Party Risk can help keep firewall firmware in your estate visible and current against advisory-driven updates.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-20295 Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |
| CVE-2026-20295 Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |
| CVE-2026-20323 Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |
| CVE-2026-20323 Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |