
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20343 is an information disclosure and denial-of-service vulnerability in Cisco Secure Firewall Management Center (FMC) Software caused by a critical API that lacks authentication. An unauthenticated, remote attacker can exploit this flaw to download sensitive restricted files and consume unbounded disk space, potentially rendering the device unresponsive. The vulnerability affects Cisco Secure FMC Software versions 7.3.0 through 10.0.1 across numerous releases. It was publicly disclosed on September 16, 2026, as part of a broader Cisco security advisory (cisco-sa-fmc-mulivulns-4PsnFwvx) and carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, GitHub Advisory).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function) — a critical API endpoint in Cisco Secure FMC Software is exposed without any authentication requirement. An attacker can exploit this by sending repeated unauthenticated network requests directly to the vulnerable API endpoint, requiring no credentials, no user interaction, and no special configuration on the target device. The dual impact arises from the same unauthenticated API call: it can serve restricted files to the requester and simultaneously generate unbounded disk writes or storage consumption on the FMC appliance. Cisco Bug ID CSCwu36643 tracks this specific issue (Cisco Advisory).
Successful exploitation has two distinct consequences: an attacker can download sensitive files that should be access-controlled (confidentiality impact), and by repeatedly invoking the API, can exhaust available disk space on the FMC appliance, causing it to become unresponsive and triggering a denial-of-service condition (availability impact). Because the FMC is a centralized management platform for Cisco Firepower security devices, its unavailability could disrupt firewall policy management and visibility across the entire managed network. The CVSS scoring reflects a high availability impact with no integrity or confidentiality impact in the base score, though the advisory narrative explicitly notes sensitive file download as a consequence (Cisco Advisory, GitHub Advisory).
No public proof-of-concept exploit code has been identified, and Cisco PSIRT has confirmed it is not aware of any public announcements or malicious use of this vulnerability at the time of disclosure. The EPSS score is 0.0, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported to Cisco by Christophe Schleypen from the NATO Cyber Security Centre (NCSC) (Cisco Advisory).
Cisco has released software updates that address this vulnerability; there are no workarounds available. Administrators should use the Cisco Software Checker tool to identify the appropriate fixed release for their deployment and upgrade immediately. As an interim measure, network-level access controls (e.g., firewall rules, ACLs) should be implemented to restrict access to the FMC management interface to trusted IP addresses only. Disk space usage and API invocation patterns should be monitored for signs of exploitation until patching is complete (Cisco Advisory).
The vulnerability was reported to Cisco by Christophe Schleypen from the NATO Cyber Security Centre (NCSC), indicating it was identified through responsible disclosure by a government-affiliated security organization. Cisco PSIRT confirmed no public exploitation or announcements at the time of disclosure. The advisory was part of a broader September 16, 2026 release covering five CVEs in Cisco Secure FMC Software, with the most severe (CVE-2026-20341) rated Critical at CVSS 9.1 (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."