Cisco FMC SQL injection CVE-2026-20344: monitoring plan
An authenticated SQL injection, CVE-2026-20344 (CVSS 8.8, CWE-89), was found in the Cisco Secure Firewall Management Center web interface. It requires a Security Approver, Access Admin or Network Admin account; the only fix is an update, with no workarounds.
- CVSS 3.1 is 8.8, vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Cisco published advisory on September 16, 2026 with no workarounds
- CERT-In CIVN-2026-0464: two vulnerabilities already exploited
- ZoomEye indexes 828 exposed FMC assets
Read next
Security