Cisco Secure Firewall Manageme... Note

Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability

A critical vulnerability has been identified in Cisco Secure Firewall Management Center (FMC) Software, specifically within the sftunnel inter-device communication protocol. This flaw could permit an authenticated, remote attacker to execute arbitrary commands with root privileges on affected devices. The vulnerability stems from a registered sftunnel peer possessing incorrect permissions to write an arbitrary file to any location. Attackers could exploit this by hijacking the sftunnel connection or by being a registered peer and sending a malicious command. This malicious file, once written, would be executed with root privileges. Crucially, exploitation requires the attacker to possess valid user credentials on the compromised device. Cisco has already released software updates to resolve this vulnerability. Unfortunately, there are no workarounds available to mitigate this specific issue. The security impact rating for this vulnerability is critical. The assigned CVE identifier for this vulnerability is CVE-2026-20324.