Cisco FMC SQL Injection Flaw CVE-2026-20344 Rated Critical, No Workaround Available
Cisco disclosed an authenticated SQL injection vulnerability (CVE-2026-20344) in its Secure Firewall Management Center web interface on September 16, 2026, assigning it a CVSS score of 8.8. The flaw, classified under CWE-89, can be exploited by users holding Security Approver, Access Admin, or Network Admin roles, making credential compromise a key part of the threat. India's CERT-In advisory CIVN-2026-0464 rated the broader vulnerability set as Critical and noted that two related flaws are already being exploited in the wild. No workarounds exist, meaning all affected deployments remain exposed until they are upgraded to a patched version. Security teams are advised to isolate FMC interfaces behind dedicated admin networks, enforce multi-factor authentication, audit role assignments, and correlate login anomalies with suspicious configuration changes to detect potential exploitation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in