Cisco disclosed multiple vulnerabilities in the sftunnel communication component of Secure Firewall Management Center (FMC) and Secure Firewall Threat Defense (FTD). CVE-2026-20324, rated CVSS 9.9, is a missing-authorization flaw that lets an attacker controlling or hijacking a registered sftunnel peer write arbitrary files and execute commands as root on FMC, potentially compromising the centralized management plane. Cisco reported no known malicious exploitation when it disclosed the issue.
Cisco also patched CVE-2026-20295 and CVE-2026-20323, which are associated with improper certificate validation (CWE-295). CVE-2026-20295 is network-accessible without authentication or user interaction and can cause a high-impact denial of service. Organizations should upgrade FMC and FTD to Cisco's fixed releases, as no workaround is available for the root-RCE issue, and should investigate anomalous sftunnel peer registrations or policy deployments while segmenting and monitoring the firewall management plane.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Cisco published advisory cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3 and patches for CVE-2026-20295 and CVE-2026-20323 affecting Firepower Management Center and Firepower Threat Defense. CVE-2026-20295 is a CWE-295 issue with network-reachable, low-complexity exploitation and high availability impact.
Cisco disclosed CVE-2026-20324, a CVSS 9.9 missing-authorization vulnerability in FMC sftunnel communications. An attacker controlling or hijacking a registered sftunnel peer could write arbitrary files and execute commands as root; Cisco said it was unaware of malicious exploitation and that no workaround exists.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.