Vulnerabilities & Exploits

Cisco FMC Advisory Splits Five Flaws Apart

Cisco released updates for five vulnerabilities in Secure Firewall Management Center (FMC) software on September 16, and its advisory says the flaws are independent. The bugs can let an authenticated remote attacker reach root, read sensitive files, run SQL injection, or trigger a denial of service.

The technical detail that matters is simple: one affected release may contain only some of the five flaws, and exploiting one does not require exploiting the others. Cisco ties the issues to different paths in the management code, including deserialization and web-interface handling, so a single patch or a single exposure check does not close the whole set.

For teams that run FMC as the control plane for Cisco Secure Firewall, the exposure is in the management layer itself: if a deployment sits behind a single version gate or a single review, one fixed finding can leave the rest open. The advisory does not give a workaround, so the remaining question is which of the five issues each installed release actually carries.

1 source · 7h ago

CVE-2026-20341

NVD KEV

CVSS 9.1 CRITICAL: a vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an…

CVE-2026-20340

NVD KEV

CVE-2026-20344

NVD KEV

CVE-2026-20342

NVD KEV

CVE-2026-20343

NVD KEV

Timeline

Sources

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-09-16

Every edition of this story: Cisco FMC Advisory Splits Five Flaws Apart

More from today