Description
A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device.

This vulnerability is due to incorrect initialization of encryption parameters for the AJP connector at boot time. An attacker could exploit this vulnerability by sending crafted packets to the AJP connector. A successful exploit could allow the attacker to execute commands as root and gain full control over the FMC REST APIs on the affected device.
Note: This vulnerability can be exploited only if the valid sftunnel connection between Cisco Secure FMC Software and Cisco Secure FTD Software is down.
Published: 2026-09-16
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in the initial configuration of the Apache JServ Protocol connector within Cisco Secure FMC. Because encryption parameters are not properly set during boot, an unauthenticated, remote attacker can send specially crafted packets to the AJP connector and convince it to act as a peer device. This is a CWE‑285 (Improper Authorization) weakness. This impersonation enables the attacker to execute commands with root privileges and take full control over the FMC REST APIs, leading to a complete compromise of the device.

Affected Systems

The issue affects Cisco Secure Firewall Management Center (FMC) software. No specific firmware or version range is listed in the advisory, so all current releases of FMC should be considered potentially vulnerable until a patch is applied.

Risk and Exploitability

Based on the description, it is inferred that the AJP connector must be exposed for the attack to be possible. The CVSS score of 9 indicates high severity. The EPSS score is below 1%, suggesting few observed exploits, and the vulnerability is not yet listed in CISA’s KEV catalog. However, the attack is possible over the network via the exposed AJP connector, and it requires the sftunnel link between FMC and FTD to be down. If that condition is met, the vulnerability can be exploited remotely without authentication, allowing execution of arbitrary code with root privileges. Therefore, the risk is significant for networks that expose the AJP endpoint and have an inactive sftunnel link.

Generated by OpenCVE AI on September 18, 2026 at 02:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco FMC software update that fixes the AJP connector initialization flaw.
  • Disable the AJP connector or restrict its access to the internal network so that only authorized hosts can reach it.
  • Ensure the sftunnel connection between FMC and FTD remains active; configure automatic fail‑over or monitoring to detect and restore connectivity.
  • Monitor logs for unexpected AJP traffic and investigate any anomalies.

Generated by OpenCVE AI on September 18, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Management Center
Vendors & Products Cisco
Cisco secure Firewall Management Center

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the internal configuration of the Apache JServ Protocol (AJP)&nbsp;connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to incorrect initialization of encryption parameters for the AJP connector at boot time. An attacker could exploit this vulnerability by sending crafted packets to the AJP connector. A&nbsp;successful exploit could allow the attacker to execute commands as root and&nbsp;gain full control over the FMC REST APIs on the affected device. Note: This vulnerability can be exploited only if the valid sftunnel connection between Cisco Secure FMC Software and Cisco Secure FTD Software is down.
Title Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Secure Firewall Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T11:39:24.662Z

Reserved: 2026-08-19T12:02:03.633Z

Link: CVE-2026-76420

cve-icon Vulnrichment

Updated: 2026-09-17T11:32:16.445Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T17:18:09.330

Modified: 2026-09-17T12:18:26.450

Link: CVE-2026-76420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:34Z

Weaknesses