CVE-2026-20324
Cisco Secure Firewall Management Center sftunnel arbitrary code execution lets authenticated attackers run commands as root (CVE-2026-20324)
Cisco Secure Firewall Management Center (FMC) sftunnel flaw allows an authenticated remote attacker to execute commands as root. Affected releases include 7.0.0 through 7.0.3 and 7.2.0. Cisco has a fix, but no workarounds.
What happened
A vulnerability in the sftunnel inter-device communication protocol used by Cisco Secure Firewall Management Center (FMC) Software allows an authenticated, remote attacker to execute arbitrary commands as root. The flaw exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker can exploit it by hijacking the sftunnel communication connection, or by acting as a valid registered sftunnel peer, and sending an sftunnel command that writes a malicious file to disk; that file is then executed with root privileges.
Exploitation requires valid user credentials on the affected device, but no user interaction is needed. The vulnerability is rated Critical with CVSS 3.1 score 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), reflecting network attack, low complexity, low privileges, and high impact to confidentiality, integrity and availability.
Cisco PSIRT states it is not aware of any public announcements or malicious use of the vulnerability described in this advisory.
Who is affected
Affected software is Cisco Secure Firewall Management Center (FMC) Software. The Cisco advisory lists these releases: 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3 and 7.2.0. Organisations running FMC as the management centre for Cisco Secure Firewall deployments should check their release against this list.
What to do now
- Treat this as a critical update. Cisco states a fix is available, but the fixed release numbers are not listed in the data provided on this page. Confirm the correct target release for your current version in the Cisco advisory before upgrading.
- Apply the fixed release through normal change management once you have identified it.
- Do not rely on a workaround: Cisco states there are no workarounds that address this vulnerability.
- Until patched, review and restrict sftunnel peers to only the devices that need to communicate with the FMC, since exploitation requires a registered peer or a hijacked connection.
How to detect it
Cisco has not published indicators of compromise for this CVE. Because successful exploitation results in a malicious file being written and executed with root privileges, start by auditing authorised sftunnel peers and monitoring the FMC for unexpected file writes or processes.
Beyond the patch
Beyond the patch, this is a third-party risk issue in a high-trust management platform: a single FMC manages large parts of a firewall estate, so a root-level compromise can cascade. Our Supply Chain Defense & Third-Party Risk service helps organisations maintain an accurate view of where Cisco FMC and similar vendor management systems are deployed, so critical updates reach the right owners quickly.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |