Sceawere

Vulnerability Detail

CVE-2026-20341UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Cisco FMC Insecure Deserialization Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
1d ago
Vendor
Cisco
Product
Cisco Secure Firewall Management Center (FMC)
Attack Type
Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges. This vulnerability is due to unsecured deserialization of untrusted data over the sftunnel management connection. An attacker could exploit this vulnerability by sending crafted sftunnel remote procedure calls (RPCs). A successful exploit could allow the attacker to gain root privileges on a device that is running Cisco Secure FMC Software and its high-availability peer. To exploit this vulnerability, the attacker must have valid administrative credentials on a managed Cisco FTD device.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-09-16T20:17:24.193Z",
  "pubdate": "2026-09-16T20:17:24.193Z",
  "executiveSummary": "This vulnerability involves an insecure deserialization flaw within the sftunnel inter-device communication protocol utilized by Cisco Secure FMC Software.\nAn authenticated, remote attacker can leverage this weakness to execute arbitrary code with root privileges on the affected device and its high-availability peer.\nThe vulnerability resides in the processing of untrusted data transmitted over the sftunnel management channel.\nSuccessful exploitation requires the attacker to possess valid administrative credentials on a managed Cisco FTD device, which serves as the vector to target the FMC.\nThe risk implication is critical, as it allows for full system compromise, granting an attacker complete control over the security management infrastructure.\nThe exploit relies on the transmission of malformed or crafted remote procedure calls (RPCs) that, when processed by the sftunnel component, trigger the insecure deserialization vulnerability.\nGiven the requirement for administrative authentication, this vulnerability represents an escalation of privilege from the managed device level to the management server (FMC) root level.",
  "technicalDetails": "The vulnerability is rooted in the improper handling of serialized objects within the sftunnel communication protocol, which Cisco Secure FMC Software uses to maintain synchronization and management connectivity with FTD devices.\nInsecure deserialization occurs when the sftunnel process accepts serialized data from a remote source and reconstructs it without adequate validation or sanitization of the underlying class types.\nWhen a malicious actor provides a crafted payload via an RPC call, the sftunnel component may deserialize objects that contain unexpected or harmful state definitions. If the application environment includes gadget chains capable of arbitrary code execution upon object instantiation or destruction, the attacker can hijack the execution flow.\nThe attack flow proceeds as follows: First, the attacker must establish legitimate access to a managed Cisco FTD device using administrative credentials. Once authenticated, the attacker initiates a crafted sftunnel RPC request directed toward the Cisco Secure FMC Software management node.\nBecause the communication is established between the FTD and the FMC, the RPC request reaches the vulnerable sftunnel service on the FMC. The service deserializes the input provided within the RPC, enabling the attacker to force the execution of arbitrary commands or code.\nBy achieving arbitrary code execution within the context of the sftunnel service, which operates with elevated system permissions, the attacker gains root-level control over the FMC platform. Due to the architecture of high-availability configurations in Cisco Secure FMC, the exploitation of this vulnerability on the primary node can propagate or enable further unauthorized access to the high-availability peer device.\nThe impact of this vulnerability is total system compromise. An attacker with root privileges can bypass all security controls, modify security policies, exfiltrate sensitive configuration data, or deploy persistent backdoors within the FMC environment. The dependency on administrative credentials for a managed device acts as a significant constraint, effectively limiting the scope to those who have already achieved an initial foothold within the managed network segment or have compromised device-level administrative accounts."
}