Description
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to exhaust the available memory of an affected device.

This vulnerability is due to improper management of memory resources during sftunnel TLS connection setup. An attacker could exploit this vulnerability by sending crafted sftunnel TLS frames to an affected device during the connection setup. A successful exploit could allow the attacker to exhaust the available memory on the affected device, which could result in a DoS condition.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Exhaustion DoS
Action: Apply Patch
AI Analysis

Impact

A flaw in the sftunnel inter‑device protocol of Cisco Secure Firewall Management Center and Cisco Secure Firewall Threat Defense allows an attacker to send specially crafted TLS frames during connection setup, causing the application to fail to release memory allocations. This results in a progressive depletion of available memory that can halt the device or force it to restart, producing a denial of service outcome. The vulnerability arises from improper resource cleanup during TLS handshake and can be triggered without any prior authentication.

Affected Systems

The vulnerability affects Cisco Secure Firewall Management Center (FMC) and Cisco Secure Firewall Threat Defense (FTD) software. Any managed device running either FMC or FTD and using the sftunnel TLS communication channel is potentially compromised. The impact is limited to systems that have this inter‑device protocol active.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity level. The EPSS score of less than 1% suggests that the probability of exploitation in the wild is low, and the vulnerability is not listed in the CISA KEV catalog. Attackers can remotely send crafted TLS frames without authentication, making the vector network‑based and potentially automated. Successful exploitation would require only communication to the target device’s sftunnel port and would not require any privileged access.

Generated by OpenCVE AI on September 17, 2026 at 22:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update all Cisco FMC and FTD appliances to the latest released versions that contain the sftunnel TLS memory management fix
  • If an immediate update is not possible, restrict or drop sftunnel TLS traffic from external sources by adjusting firewall and routing rules so that only trusted devices can initiate the protocol
  • Implement continuous monitoring of memory usage and TLS connection activity, and set alerts for anomalous memory consumption or sudden spikes in sftunnel handshake attempts

Generated by OpenCVE AI on September 17, 2026 at 22:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Management Center
Cisco secure Firewall Threat Defense
Vendors & Products Cisco
Cisco secure Firewall Management Center
Cisco secure Firewall Threat Defense

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to exhaust the available memory of an affected device. This vulnerability is due to improper management of memory resources during sftunnel TLS connection setup. An attacker could exploit this vulnerability by sending crafted sftunnel TLS frames to an affected device&nbsp;during the connection setup. A successful exploit could allow the attacker to exhaust the available memory on the affected device, which could result in a DoS condition.
Title Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Memory Exhaustion Denial of Service Vulnerability
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Cisco Secure Firewall Management Center Secure Firewall Threat Defense
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T13:40:57.982Z

Reserved: 2025-10-08T11:59:15.405Z

Link: CVE-2026-20295

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:18.091Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:09.740

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:17Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value