Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-20344
Cisco Secure Firewall Management Center vulnerability analysis and mitigation

Overview

CVE-2026-20344 is a SQL injection vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software that allows an authenticated, remote attacker to perform SQL injection attacks against an affected device. Disclosed on September 16, 2026, it affects Cisco Secure FMC Software versions 7.0.x through 10.0.1 across a wide range of releases. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Cisco Advisory, GitHub Advisory). It was reported to Cisco by Christophe Schleypen from the NATO Cyber Security Centre (NCSC) (Cisco Advisory).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from insufficient validation of user-supplied input in the FMC web-based management interface (GitHub Advisory). An attacker exploits this by sending a crafted HTTP request to the management interface, injecting malicious SQL syntax that is passed unsanitized to the underlying database. Exploitation requires the attacker to hold a valid account with one of the following roles: Security Approver, Access Admin, or Network Admin — meaning unauthenticated exploitation is not possible (Cisco Advisory). The attack vector is network-based, requires low privileges, low complexity, and no user interaction. No public proof-of-concept code has been identified at this time (Feedly).

Impact

Successful exploitation allows an attacker to extract any data from the FMC database, including session credentials of authenticated Administrators, and subsequently take actions with full administrative privileges on the affected device (Cisco Advisory). This creates a significant privilege escalation path: a lower-privileged user (Security Approver, Access Admin, or Network Admin) could effectively gain Administrator-level control over the FMC and all managed firewall devices. Given that FMC is a centralized security management platform, compromise could expose firewall policies, network topology data, and credentials across the entire managed environment, enabling lateral movement or policy manipulation.

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at the time of disclosure. Cisco's Product Security Incident Response Team (PSIRT) has confirmed it is not aware of any public announcements or malicious use of this vulnerability (Cisco Advisory). The EPSS score is 0.0, reflecting low current exploitation probability (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-accessible or internally reachable Cisco Secure FMC instances running affected versions (7.0.0 through 10.0.1) using network scanning tools or Shodan/Censys queries targeting FMC management interface ports (typically HTTPS/443).
  2. Credential Acquisition: Obtain valid credentials for an account with the Security Approver, Access Admin, or Network Admin role — through phishing, credential stuffing, or insider access.
  3. Authenticate to the FMC Web Interface: Log in to the FMC web-based management interface using the acquired credentials.
  4. Craft Malicious HTTP Request: Construct a crafted HTTP request targeting a vulnerable endpoint in the FMC management interface, embedding SQL injection payloads (e.g., UNION-based or time-based blind injection) within user-controlled input parameters.
  5. Extract Database Contents: Use the SQL injection to enumerate and dump database tables, extracting sensitive data including session tokens and Administrator credentials.
  6. Escalate Privileges: Leverage the extracted Administrator session credentials to authenticate as an Administrator and take full administrative control of the FMC and its managed firewall devices (Cisco Advisory).

Indicators of compromise

  • Network: Unusual or anomalous HTTP/HTTPS requests to the FMC web management interface from accounts with Security Approver, Access Admin, or Network Admin roles; unexpected outbound connections from the FMC host to external IPs.
  • Logs: FMC web server access logs showing crafted HTTP requests with SQL metacharacters (e.g., single quotes, UNION, SELECT, OR 1=1) in query parameters or POST body fields; repeated or automated request patterns from a single authenticated session.
  • Authentication: Unexpected Administrator-level logins or configuration changes following activity from lower-privileged accounts (Security Approver, Access Admin, Network Admin); new Administrator accounts created without authorization.
  • Database: Unusual database query patterns or errors logged in FMC application logs indicative of SQL injection attempts (e.g., syntax errors, unexpected query structures).

Mitigation and workarounds

Cisco has released fixed software versions addressing CVE-2026-20344; administrators should use the Cisco Software Checker to identify the appropriate fixed release for their deployment (Cisco Advisory). Cisco has confirmed there are no workarounds available for this vulnerability, making patching the only remediation. As interim risk reduction measures, organizations should restrict access to the FMC web management interface to authorized IP addresses via network access controls, enforce least-privilege principles for FMC role assignments, and monitor access logs for accounts with Security Approver, Access Admin, or Network Admin roles for suspicious activity.

Community reactions

The vulnerability was reported to Cisco by Christophe Schleypen from the NATO Cyber Security Centre (NCSC), indicating it was discovered through responsible disclosure by a government-affiliated security organization (Cisco Advisory). Coverage has appeared on security aggregation sites including SecurityOnline.info and AUSCERT, reflecting standard industry attention for a High-severity Cisco advisory. No notable researcher commentary or significant social media discussion has been identified beyond routine vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Related Cisco Secure Firewall Management Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20344HIGH8.8
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-76412HIGH8.5
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-76413HIGH8.2
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-20342HIGH7.7
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-20343HIGH7.5
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management