Description
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to impersonate the peer device and obtain access at the level of the manager role, which is equivalent to root.

This vulnerability is due to improper management of the TLS certificate for the sftunnel management connection. An attacker could exploit this vulnerability by connecting to the sftunnel port using a crafted TLS certificate. A successful exploit could allow the attacker to become a registered sftunnel peer with root access.
Note: The attack is successful only if the sftunnel connection is down or the attack can disrupt the sftunnel connection long enough to execute the attack.
Published: 2026-09-16
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass enabling root-level access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is caused by improper handling of the TLS certificate used in the sftunnel inter‑device communication protocol. An attacker who can connect to the sftunnel port with a crafted certificate can impersonate a peer device and become a registered sftunnel peer. The resulting compromise grants manager‑level access, which is equivalent to root, allowing the attacker full control over the device and its managed objects.

Affected Systems

Cisco Secure Firewall Management Center (FMC) and Cisco Secure Firewall Threat Defense (FTD) Software are affected. No specific version numbers are listed in the advisory, so any deployment of these products that has not been updated to the patched release is potentially vulnerable.

Risk and Exploitability

The flaw carries a CVSS score of 8.3 and an EPSS probability of less than 1%, indicating a high severity but a low likelihood of exploitation at the time of this analysis. The vulnerability is not listed in CISA KEV. The attack requires an adjacent, unauthenticated attacker with network access to the sftunnel interface; it succeeds only if the existing sftunnel connection is down or can be disrupted long enough for the attacker to introduce the forged certificate. Once exploited, the attacker gains full administrative privileges.

Generated by OpenCVE AI on September 18, 2026 at 01:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest update for Cisco Secure FMC and FTD that resolves the sftunnel TLS certificate issue, obtainable from Cisco Secure Central or the vendor portal;
  • Restrict or disable the sftunnel port so that only authorized peer devices can establish a connection, and enforce strict network segmentation or firewall rules to limit adjacency to the port;
  • Monitor TLS handshake logs on FMC/FTD for anomalous certificate exchanges and configure alerts for any attempts to connect to the sftunnel port with invalid certificates.

Generated by OpenCVE AI on September 18, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Management Center
Cisco secure Firewall Threat Defense
Vendors & Products Cisco
Cisco secure Firewall Management Center
Cisco secure Firewall Threat Defense

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to impersonate the peer device and obtain access at the level of the&nbsp;manager role, which is equivalent to root. This vulnerability is due to improper management of the TLS certificate for the sftunnel management connection. An attacker could exploit this vulnerability by connecting to the sftunnel port using a crafted TLS certificate. A successful exploit could allow the attacker to become a registered sftunnel peer with root access. Note: The attack is successful only if the sftunnel connection is down or the attack can disrupt the sftunnel connection long enough to execute the attack.
Title Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Unauthorized Authentication Bypass Vulnerability
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Secure Firewall Management Center Secure Firewall Threat Defense
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T11:39:21.989Z

Reserved: 2025-10-08T11:59:15.411Z

Link: CVE-2026-20323

cve-icon Vulnrichment

Updated: 2026-09-17T11:31:34.737Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:10.313

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:51:20Z

Weaknesses
  • CWE-295

    Improper Certificate Validation