Description
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root.

This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerability by hijacking the sftunnel communication connection or being a valid registered sftunnel peer and sending an sftunnel command to write a malicious file to the disk of an affected device. A successful exploit could allow the attacker to write a file to the device that is executed with root privileges. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
Published: 2026-09-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution with root privileges
Action: Immediate Patch
AI Analysis

Impact

A flaw in the sftunnel inter‑device communication protocol of Cisco Secure Firewall Management Center allows an authenticated remote attacker to write an arbitrary file to any location on the device. By sending a specially crafted sftunnel command, the attacker can store a malicious file that is later executed with root privileges, effectively enabling remote code execution as root.

Affected Systems

The vulnerability applies to Cisco Secure Firewall Management Center (FMC). No specific firmware or software version information is provided in the CVE entry; users should consult the Cisco advisory linked in the references to confirm whether their deployments are affected.

Risk and Exploitability

The CVSS score of 9.9 indicates very high severity. The EPSS score of less than 1% suggests a low probability of exploitation in the near term, but the flaw can only be leveraged by users possessing valid credentials and by hijacking or constructing a sftunnel connection. The vulnerability is not listed in the CISA KEV catalog. Abuse of this weakness, identified as CWE‑862, would allow an attacker to bypass permission checks and gain root-level code execution, which would be a critical incident if an exploit succeeds.

Generated by OpenCVE AI on September 18, 2026 at 01:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco Secure Firewall Management Center patch or upgrade to a release that fixes the sftunnel file‑write issue.
  • Limit or disable the sftunnel peer registration feature on devices that do not need inter‑device communication, or restrict peer registration to trusted devices only.
  • Enforce strict authentication requirements by ensuring that only privileged accounts can configure or manage sftunnel peers; consider disabling explicit write permissions for non‑administrator users.

Generated by OpenCVE AI on September 18, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Management Center
Vendors & Products Cisco
Cisco secure Firewall Management Center

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerability by hijacking the sftunnel communication connection or being a valid registered sftunnel peer and sending an sftunnel command to write a malicious file to the disk of an affected device. A successful exploit could allow the attacker to write a file to the device that is executed with root privileges. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
Title Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Secure Firewall Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T03:55:52.045Z

Reserved: 2025-10-08T11:59:15.411Z

Link: CVE-2026-20324

cve-icon Vulnrichment

Updated: 2026-09-17T16:04:55.103Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:23.180

Modified: 2026-09-18T04:17:37.867

Link: CVE-2026-20324

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:38Z

Weaknesses