Cisco Patches Critical CVE-2026-20324 Flaw in Firewall Management Center
Cisco disclosed a critical vulnerability, CVE-2026-20324, in the sftunnel component of its Secure Firewall Management Center (FMC) on September 16, 2026, as part of a broader wave of security fixes. Rated CVSS 9.9, the flaw allows an unauthenticated remote attacker to execute arbitrary code with root privileges without requiring any user interaction or valid credentials. Because FMC centrally distributes policy and configuration to managed firewall devices, a successful compromise could let attackers alter access rules, disable logging, and move laterally across protected network segments. Cisco stated it was unaware of any public exploitation or malicious use at the time of disclosure, and free software updates have been released for all affected versions. Until patches are applied, administrators are advised to restrict management-plane access to trusted hosts and dedicated subnets, and to monitor tunnel activity for anomalous sessions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in