Free delivery

GGuestNot signed in
You're not signed in
LoginCreate account

9/22/2026 • Security

Cisco Fixes a Root Flaw in Its Firewall Management Center

Cisco has patched five flaws in Secure Firewall Management Center, including a CVSS 9.1 bug that lets an already-authenticated attacker reach root over the management channel — the latest in a year where FMC itself has become the target.

Cisco has patched five vulnerabilities in Secure Firewall Management Center (FMC) — the console that administrators use to configure and monitor their Cisco firewalls — and the standout is a flaw that lets an attacker who already has a foothold turn it into root access on the box that manages everything else. It's not the most dangerous bug FMC has had this year, and it isn't (yet) being exploited. But it lands in the middle of a pattern worth paying attention to: the software meant to watch your firewalls has itself become one of 2026's most fought-over targets.

What happened, in plain English

On 16 September 2026, Cisco published advisory cisco-sa-fmc-mulivulns-4PsnFwvx, covering five separate flaws in FMC. They're independent bugs — fixing one doesn't fix another — but they share a theme: several involve the software trusting data it shouldn't.

The headline bug is CVE-2026-20341 (CVSS 9.1), in sftunnel, the encrypted management channel FMC uses to talk to the Cisco Firepower Threat Defense (FTD) firewalls it controls. FMC unsafely deserialises data arriving over that channel, and a crafted message can hand an attacker root privileges on the FMC box — and its high-availability partner, if it has one. The important nuance: this isn't reachable by a random stranger on the internet. The attacker needs valid administrative credentials on a managed FTD device first. It's a serious escalation bug, not an open door.

The one that should worry a defender more, arguably, is CVE-2026-20340 (CVSS 8.8): the same class of unsafe deserialization, but reachable through FMC's ordinary web management interface, and it only requires an account with the Security Analyst (read-only) role — Cisco's lowest management privilege level. A successful attack turns a low-value, read-only login into full root on the device. If that account is ever phished or reused from a breached password list, the blast radius is total.

The remaining three are lower-severity but still real: CVE-2026-20344 (CVSS 8.8) is a SQL injection reachable by a Security Approver, Access Admin or Network Admin account, letting them pull data straight from FMC's database — including other administrators' session credentials. CVE-2026-20342 (CVSS 7.7) lets a Security Analyst download files they shouldn't be able to reach. And CVE-2026-20343 (CVSS 7.5) is the only one of the five that needs no credentials at all — an unauthenticated attacker can hit an unprotected API to pull restricted files and fill up disk space, which can knock the appliance offline.

Cisco says it isn't aware of any of the five being exploited or publicly discussed before the patch shipped, and there are no workarounds — the only fix is to upgrade. Cisco's guidance is to run the affected release through the Cisco Software Checker to confirm the exact fixed train for your version.

Why it matters: the console itself is the target

One bundle of unexploited bugs, on its own, wouldn't be much of a story — vendors patch things constantly, and that's the system working. What makes this worth a longer look is what it sits on top of. FMC has had a genuinely difficult 2026:

  • In March, Cisco patched CVE-2026-20131, a CVSS 10.0 flaw where unsafe Java deserialization let an unauthenticated attacker get root over FMC's web interface — no credentials needed at all.
  • In July, security researcher Jimi Sebree reported CVE-2026-20316, hard-coded static credentials in FMC that let anyone log in without a real account. CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue after confirming Qilin ransomware affiliates were already using it for reconnaissance.
  • In September, Cisco confirmed CVE-2026-20079 — a CVSS 10.0 authentication bypass caused by a leftover boot-time session — was being actively exploited, including by the Sandworm/GRU-linked group deploying the Cyclops Blink implant. CISA added it to KEV on 9 September with a compressed federal patch deadline of 12 September.

That's three separate root-level or authentication-bypass flaws in FMC confirmed exploited in the wild inside a single year, plus now a fourth bundle of fixes for the same broad category of bug. None of September's five new flaws are known to be exploited yet — but the pattern is the lesson: FMC isn't just another appliance on the network. It's the single console with authority over every firewall it manages, which makes it one of the highest-value targets an attacker can reach, and this year that theory has been proven in practice more than once.

The honest bit

We sell Cisco and Meraki gear, and no vendor is immune from this — including ones we like. To Cisco's credit here: these five flaws were caught and patched before anyone is known to have used them, PSIRT was upfront about that, and the advisory is clear about which roles are needed for each bug rather than inflating the severity. That's what responsible disclosure looks like, and it's a different story to the three flaws above that were caught only after attackers were already inside.

One genuine, non-salesy difference worth knowing: centrally cloud-managed platforms like Meraki don't carry an on-premises management console with this exact attack surface, because the management plane isn't a box sitting in your server room that you have to patch, harden and monitor yourself — updates are pushed by the vendor. That's a real architectural difference, not a knock on FMC, which exists to do a job Meraki's model handles differently.

What we'd suggest you actually do

  1. Find out if you run FMC. If you don't manage on-box Cisco firewalls through a Secure Firewall Management Center instance, none of this applies to you.
  2. Check your version against Cisco's Software Checker for this advisory and the March/July/September flaws above, and patch to a fixed release — there's no workaround for any of them.
  3. Get the FMC management interface off the open internet. It should only ever be reachable from a trusted internal network or a VPN — every one of this year's FMC flaws assumed network reachability to the web UI or the sftunnel channel.
  4. Tighten account hygiene now, not later. CVE-2026-20340 shows a read-only Security Analyst account is enough to reach root. Enforce MFA, unique credentials, and least-privilege roles for every FMC login.
  5. Given the credential-based exploitation already seen this year (CVE-2026-20316), rotate FMC admin credentials if you haven't done so since July, and review login and sftunnel logs for anything unfamiliar.
  6. Subscribe to Cisco PSIRT advisories so the next one reaches you the day it's published, not the month after.

The friendly takeaway

This particular bundle of fixes is Cisco doing things right — five bugs, caught and patched before exploitation. But it lands on top of a year where the box managing your Cisco firewalls has repeatedly turned out to be the thing attackers went after first. Patch it, get it off the internet, and treat its logins with the same seriousness as your domain admin account — because for anyone who compromises it, that's effectively what it is.

As always, this is us keeping watch so you don't have to. If you'd like a second pair of eyes on what's exposed in your network — including anything managing your firewalls — get in touch. No obligation, no hard sell.

References

Contact Us

Email: [email protected]

Phone: 1300 989 334

About

Your one-stop technology hub for all your networking, security, and IT needs. From cutting-edge networking solutions to robust security products, we provide everything your business requires to stay connected, secure, and efficient. Whether you're looking for advanced hardware, software, or services, we offer reliable, innovative technology tailored to help you build and protect your digital infrastructure.

Copyright © 2026 TYONLINE TECHNOLOGY PTY. LTD. All Rights Reserved.