SB20260917231 - Multiple vulnerabilities in Cisco Secure Firewall Management Center and Secure Firewall Threat Defense
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 12 vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2026-76412)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to an error when checking the privilege level of a user who is invoking remote diagnostics. A remote user can use the remote diagnostics debugger to gain elevated privileges.
2) Improper Restriction of Security Token Assignment (CVE-ID: CVE-2026-76413)
CWE-ID: CWE-1259 - Improper Restriction of Security Token Assignment
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper management of the Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) token. A remote attacker can perform session token forgery techniques to log in as the administrator user and keep legitimate administrators locked out of the ASDM indefinitely.
3) Improper Authorization (CVE-ID: CVE-2026-76420)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to incorrect initialization of encryption parameters for the Apache JServ Protocol (AJP) connector at boot time. A remote attacker can send specially crafted packets to the AJP connector and execute arbitrary commands on the target system.
4) Improper Certificate Validation (CVE-ID: CVE-2026-20323)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper management of the TLS certificate for the sftunnel management connection. A remote attacker on the local network can become a registered sftunnel peer with root access.
5) Uncontrolled Memory Allocation (CVE-ID: CVE-2026-20295)
CWE-ID: CWE-789 - Uncontrolled Memory Allocation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of memory resources during sftunnel TLS connection setup. A remote attacker can cause a denial of service (DoS) condition on the target system.
6) SQL injection (CVE-ID: CVE-2026-20344)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the web-based management interface. A remote user can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
7) Missing Authentication for Critical Function (CVE-ID: CVE-2026-20343)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the critical API lacks authentication. A remote attacker can download sensitive files that should be restricted and consume disk space to perform a denial of service (DoS) attack.
8) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-20342)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to improper input validation in a specific file download API. A remote user can send a specially crafted HTTPS request and download arbitrary files from the affected system.
9) Deserialization of Untrusted Data (CVE-ID: CVE-2026-20341)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to unsecured deserialization of untrusted data over the sftunnel management connection. A remote administrator can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
10) Deserialization of Untrusted Data (CVE-ID: CVE-2026-20340)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to unsecured deserialization of web-management user-controlled data. A remote user can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
11) Missing Authorization (CVE-ID: CVE-2026-20324)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to the registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. A remote user can write a file to the device that is executed with root privileges.
12) Deserialization of Untrusted Data (CVE-ID: CVE-2026-20242)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data in the External Database Access feature. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
Install update from vendor's website.
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc2-multivulns-HXgcqRG
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sftunn-codex-c3O4Jft2
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk