Description
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges.

This vulnerability is due to unsecured deserialization of untrusted data over the sftunnel management connection. An attacker could exploit this vulnerability by sending crafted sftunnel remote procedure calls (RPCs). A successful exploit could allow the attacker to gain root privileges on a device that is running Cisco Secure FMC Software and its high-availability peer.
To exploit this vulnerability, the attacker must have valid administrative credentials on a managed Cisco FTD device.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Root Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Unsecured deserialization of data sent over the sftunnel inter‑device communication protocol allows an attacker who possesses valid administrative credentials on a managed FTD device to send crafted remote procedure calls. When processed, the vulnerability permits execution of arbitrary commands with the privileges of the running daemon, effectively granting root privileges on the device and its high‑availability peer. This type of flaw is classified as CWE‑502, insecure deserialization, which can lead to complete compromise of the affected appliance.

Affected Systems

Cisco Secure Firewall Management Center (FMC) installs that use the sftunnel protocol are affected. No specific version information was supplied in the CNA data, so all released FC‑secure versions should be assumed vulnerable until Cisco issues a patch.

Risk and Exploitability

The CVSS score of 9.1 marks this as a critical vulnerability; however, the EPSS score of less than 1 percent indicates a very low likelihood of exploitation in the wild at this time. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been confirmed yet. Attackers must first authenticate as a valid administrator on a device that uses the sftunnel interface, which limits the threat to privileged insiders or attackers who have compromised an admin account. With those credentials, an attacker can remotely trigger the malicious RPCs and gain root-level access, allowing unrestricted modification or takeover of the device.

Generated by OpenCVE AI on September 18, 2026 at 00:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco Secure Firewall Management Center patch or update that addresses the sftunnel deserialization flaw.
  • Disable the sftunnel service on devices where it is not required, reducing the attack surface.
  • Ensure that administrative access is restricted to trusted users, enforce strong authentication mechanisms, and monitor for anomalous RPC activity.

Generated by OpenCVE AI on September 18, 2026 at 00:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Management Center
Vendors & Products Cisco
Cisco secure Firewall Management Center

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain&nbsp;root privileges. This vulnerability is due to unsecured deserialization of untrusted data over the sftunnel management connection. An attacker could exploit this vulnerability by sending crafted sftunnel remote procedure calls (RPCs). A successful exploit could allow the attacker to gain root privileges on a device that is running Cisco Secure FMC Software and its high-availability peer. To exploit this vulnerability, the attacker must have valid administrative credentials on a managed Cisco FTD device.
Title Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Secure Firewall Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T03:55:58.880Z

Reserved: 2025-10-08T11:59:15.413Z

Link: CVE-2026-20341

cve-icon Vulnrichment

Updated: 2026-09-17T16:04:21.399Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:24.193

Modified: 2026-09-18T04:17:47.180

Link: CVE-2026-20341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:22Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data