Improper Authorization in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2026-76420
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to incorrect initialization of encryption parameters for the Apache JServ Protocol (AJP) connector at boot time. A remote attacker can send specially crafted packets to the AJP connector and execute arbitrary commands on the target system.