Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-20343
Cisco Secure Firewall Management Center vulnerability analysis and mitigation

Overview

CVE-2026-20343 is an information disclosure and denial-of-service vulnerability in Cisco Secure Firewall Management Center (FMC) Software caused by a critical API that lacks authentication. An unauthenticated, remote attacker can exploit this flaw to download sensitive restricted files and consume unbounded disk space, potentially rendering the device unresponsive. The vulnerability affects Cisco Secure FMC Software versions 7.3.0 through 10.0.1 across numerous releases. It was publicly disclosed on September 16, 2026, as part of a broader Cisco security advisory (cisco-sa-fmc-mulivulns-4PsnFwvx) and carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-306 (Missing Authentication for Critical Function) — a critical API endpoint in Cisco Secure FMC Software is exposed without any authentication requirement. An attacker can exploit this by sending repeated unauthenticated network requests directly to the vulnerable API endpoint, requiring no credentials, no user interaction, and no special configuration on the target device. The dual impact arises from the same unauthenticated API call: it can serve restricted files to the requester and simultaneously generate unbounded disk writes or storage consumption on the FMC appliance. Cisco Bug ID CSCwu36643 tracks this specific issue (Cisco Advisory).

Impact

Successful exploitation has two distinct consequences: an attacker can download sensitive files that should be access-controlled (confidentiality impact), and by repeatedly invoking the API, can exhaust available disk space on the FMC appliance, causing it to become unresponsive and triggering a denial-of-service condition (availability impact). Because the FMC is a centralized management platform for Cisco Firepower security devices, its unavailability could disrupt firewall policy management and visibility across the entire managed network. The CVSS scoring reflects a high availability impact with no integrity or confidentiality impact in the base score, though the advisory narrative explicitly notes sensitive file download as a consequence (Cisco Advisory, GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and Cisco PSIRT has confirmed it is not aware of any public announcements or malicious use of this vulnerability at the time of disclosure. The EPSS score is 0.0, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported to Cisco by Christophe Schleypen from the NATO Cyber Security Centre (NCSC) (Cisco Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Cisco Secure FMC appliances running affected versions (7.3.0 through 10.0.1) using network scanning tools such as Shodan, Censys, or Nmap targeting common FMC management ports.
  2. Identify the unauthenticated API endpoint: Enumerate the FMC web management interface to locate the critical API endpoint that lacks authentication controls (specific endpoint details have not been publicly disclosed).
  3. Send unauthenticated API requests: Craft and send HTTP/HTTPS requests to the vulnerable API endpoint without supplying any credentials or authentication tokens.
  4. Download sensitive files: Leverage the API's file-serving functionality to retrieve restricted files from the FMC system, potentially including configuration data, credentials, or policy information.
  5. Trigger DoS via disk exhaustion: Repeatedly invoke the API in rapid succession to generate unbounded disk space consumption on the FMC appliance, causing the device to become unresponsive and denying management access to legitimate administrators (Cisco Advisory).

Indicators of compromise

  • Network: Unusual or high-volume unauthenticated HTTP/HTTPS requests to the FMC management interface from external or unexpected IP addresses; repeated API calls to the same endpoint without authentication headers.
  • Logs: FMC web server access logs showing repeated requests to a specific API path from a single or rotating source IP without session tokens or authentication; error logs indicating disk space warnings or filesystem full conditions.
  • File System: Rapid or unexpected growth in FMC disk usage, particularly in directories associated with API response caching or temporary file storage; presence of unexpected files in download or temp directories.
  • Availability: FMC appliance becoming unresponsive or slow to respond to legitimate administrator logins; management interface timeouts correlating with high API request volume (Cisco Advisory).

Mitigation and workarounds

Cisco has released software updates that address this vulnerability; there are no workarounds available. Administrators should use the Cisco Software Checker tool to identify the appropriate fixed release for their deployment and upgrade immediately. As an interim measure, network-level access controls (e.g., firewall rules, ACLs) should be implemented to restrict access to the FMC management interface to trusted IP addresses only. Disk space usage and API invocation patterns should be monitored for signs of exploitation until patching is complete (Cisco Advisory).

Community reactions

The vulnerability was reported to Cisco by Christophe Schleypen from the NATO Cyber Security Centre (NCSC), indicating it was identified through responsible disclosure by a government-affiliated security organization. Cisco PSIRT confirmed no public exploitation or announcements at the time of disclosure. The advisory was part of a broader September 16, 2026 release covering five CVEs in Cisco Secure FMC Software, with the most severe (CVE-2026-20341) rated Critical at CVSS 9.1 (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Secure Firewall Management Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20344HIGH8.8
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-76412HIGH8.5
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-76413HIGH8.2
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-20342HIGH7.7
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-20343HIGH7.5
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management