A critical (CVSS 9.1) insecure deserialization bug in the sftunnel protocol of Cisco Secure Firewall Management Center could, according to Cisco's advisory, allow an authenticated remote attacker to escalate to root on the FMC appliance and its high-availability peer.
What Is It
CVE-2026-20341 is a deserialization of untrusted data flaw (CWE-502) in the sftunnel inter-device communication protocol used by Cisco Secure FMC Software. Cisco describes the sftunnel management connection as accepting serialized data without adequate validation, such that an attacker who can send crafted sftunnel remote procedure calls (RPCs) across that channel may be able to execute their payload with root privileges.
Exploitation requires valid administrative credentials on a managed Cisco FTD device; the CVSS vector reflects this as PR:H (high privileges required) with AV:N/AC:L/UI:N. The scope is marked Changed (S:C), which is the key detail: compromise of a managed FTD device propagates upward into the manager itself.
Why It Matters
FMC is the management plane for a fleet of firewalls. The Changed scope, combined with the root-level impact Cisco describes, implies that an attacker who has already taken an FTD device, or who obtained admin credentials for one, could pivot from a single managed endpoint to root on the central management server, and the advisory's reference to the HA peer suggests that reach extends there as well. If that chain holds in practice, a contained device compromise becomes control of firewall policy across the environment, with rule changes, credential access, and logging suppression all plausibly within reach. Cisco has not published exploitation mechanics that would let us confirm how far the chain runs in a real deployment.
Impact is High across confidentiality, integrity, and availability (C:H/I:H/A:H), with an impact subscore of 6.0 and exploitability subscore of 2.3.
No CISA KEV record accompanies this source material, so the exploitation status of CVE-2026-20341 cannot be characterized from what is available here; the absence of an entry is not itself evidence that the flaw is unexploited, and no KEV-mandated remediation deadline appears in these sources.
What's Vulnerable
Cisco Secure Firewall Management Center (FMC) Software. The affected list supplied by Cisco PSIRT spans essentially every maintenance release across the 7.0, 7.2, 7.3, 7.4, 7.6, 7.7, and 10.0 trains; from 7.0.0 through 7.0.9, 7.2.0 through 7.2.11, 7.3.0 through 7.3.1.2, 7.4.0 through 7.4.7, 7.6.0 through 7.6.5, 7.7.0 through 7.7.12, and 10.0.0 / 10.0.1.
No affected CPE entries were published, and NVD lists the record as Awaiting Analysis as of its last modification on 2026-09-16.
Patch Status
The supplied NVD record does not enumerate fixed versions. Cisco published this as part of a multi-vulnerability advisory (cisco-sa-fmc-mulivulns-4PsnFwvx) on 2026-09-16; consult that advisory for fixed-release mapping against your deployed train.
Sources
- NVD, CVE-2026-20341: https://nvd.nist.gov/vuln/detail/CVE-2026-20341
- Cisco Security Advisory; cisco-sa-fmc-mulivulns-4PsnFwvx: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx