CVE-2026-20324
CVE-2026-20324: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Cisco
1 advisory- Advisory severityCritical9.9
Critical [CVE-2026-20324] Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability
cisco-sa-fmc-sftunn-codex-c3O4Jft2Source published Source updated
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerability by hijacking the sftunnel communication connection or being a valid registered sftunnel peer and sending an sftunnel command to write a malicious file to the disk of an affected device. A successful exploit could allow the attacker to write a file to the device that is executed with root privileges. To exploit this vulnerability, the attacker must have valid user credentials on the affected…
- Affected products in this advisory
- Secure Firewall Management Center (FMC) Appliances
- Source-reported affected versions
- Scope: This vulnerability affects Cisco Secure FMC Software if sftunnel is enabled (sftunnel is enabled by default). For an overview of the sftunnel protocol, see Configure, Verify, and Troubleshoot Firepower Device Registration.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
- Workarounds
- There are no workarounds that address this vulnerability.
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.