
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20344 is a SQL injection vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software that allows an authenticated, remote attacker to perform SQL injection attacks against an affected device. Disclosed on September 16, 2026, it affects Cisco Secure FMC Software versions 7.0.x through 10.0.1 across a wide range of releases. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Cisco Advisory, GitHub Advisory). It was reported to Cisco by Christophe Schleypen from the NATO Cyber Security Centre (NCSC) (Cisco Advisory).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from insufficient validation of user-supplied input in the FMC web-based management interface (GitHub Advisory). An attacker exploits this by sending a crafted HTTP request to the management interface, injecting malicious SQL syntax that is passed unsanitized to the underlying database. Exploitation requires the attacker to hold a valid account with one of the following roles: Security Approver, Access Admin, or Network Admin — meaning unauthenticated exploitation is not possible (Cisco Advisory). The attack vector is network-based, requires low privileges, low complexity, and no user interaction. No public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation allows an attacker to extract any data from the FMC database, including session credentials of authenticated Administrators, and subsequently take actions with full administrative privileges on the affected device (Cisco Advisory). This creates a significant privilege escalation path: a lower-privileged user (Security Approver, Access Admin, or Network Admin) could effectively gain Administrator-level control over the FMC and all managed firewall devices. Given that FMC is a centralized security management platform, compromise could expose firewall policies, network topology data, and credentials across the entire managed environment, enabling lateral movement or policy manipulation.
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at the time of disclosure. Cisco's Product Security Incident Response Team (PSIRT) has confirmed it is not aware of any public announcements or malicious use of this vulnerability (Cisco Advisory). The EPSS score is 0.0, reflecting low current exploitation probability (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Cisco has released fixed software versions addressing CVE-2026-20344; administrators should use the Cisco Software Checker to identify the appropriate fixed release for their deployment (Cisco Advisory). Cisco has confirmed there are no workarounds available for this vulnerability, making patching the only remediation. As interim risk reduction measures, organizations should restrict access to the FMC web management interface to authorized IP addresses via network access controls, enforce least-privilege principles for FMC role assignments, and monitor access logs for accounts with Security Approver, Access Admin, or Network Admin roles for suspicious activity.
The vulnerability was reported to Cisco by Christophe Schleypen from the NATO Cyber Security Centre (NCSC), indicating it was discovered through responsible disclosure by a government-affiliated security organization (Cisco Advisory). Coverage has appeared on security aggregation sites including SecurityOnline.info and AUSCERT, reflecting standard industry attention for a High-severity Cisco advisory. No notable researcher commentary or significant social media discussion has been identified beyond routine vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."