Cisco FMC sftunnel flaw CVE-2026-20324 explained
A critical vulnerability, CVE-2026-20324, was found in the sftunnel component of Cisco Secure Firewall Management Center with a CVSS score of 9.9. An unauthenticated remote attacker can execute arbitrary code as root; patches were released on September 16, 2026.
- CVSS 9.9: unauthenticated code execution with root privileges
- The encrypted sftunnel channel between FMC and managed firewalls is affected
- Patches released September 16, 2026 alongside ASA and FTD fixes
- No workarounds; restrict access to the management plane
Read next
Security