CVE-2026-76420 is a vulnerability in Cisco Secure Firewall Management Center
Published on September 16, 2026
Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability
A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device.
This vulnerability is due to incorrect initialization of encryption parameters for the AJP connector at boot time. An attacker could exploit this vulnerability by sending crafted packets to the AJP connector. A successful exploit could allow the attacker to execute commands as root and gain full control over the FMC REST APIs on the affected device.
Note: This vulnerability can be exploited only if the valid sftunnel connection between Cisco Secure FMC Software and Cisco Secure FTD Software is down.
Vulnerability Analysis
CVE-2026-76420 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-76420 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-76420
Want to know whenever a new CVE is published for Cisco Secure Firewall Management Center? stack.watch will email you.
Affected Versions
Cisco Secure Firewall Management Center (FMC):- Version 7.0.0 is affected.
- Version 7.0.0.1 is affected.
- Version 7.0.1 is affected.
- Version 7.0.1.1 is affected.
- Version 7.0.2 is affected.
- Version 7.2.0 is affected.
- Version 7.0.2.1 is affected.
- Version 7.0.3 is affected.
- Version 7.2.0.1 is affected.
- Version 7.0.4 is affected.
- Version 7.2.1 is affected.
- Version 7.0.5 is affected.
- Version 7.3.0 is affected.
- Version 7.2.2 is affected.
- Version 7.3.1 is affected.
- Version 7.2.3 is affected.
- Version 7.2.3.1 is affected.
- Version 7.2.4 is affected.
- Version 7.0.6 is affected.
- Version 7.2.4.1 is affected.
- Version 7.2.5 is affected.
- Version 7.3.1.1 is affected.
- Version 7.4.0 is affected.
- Version 7.0.6.1 is affected.
- Version 7.2.5.1 is affected.
- Version 7.4.1 is affected.
- Version 7.2.6 is affected.
- Version 7.4.1.1 is affected.
- Version 7.0.6.2 is affected.
- Version 7.2.7 is affected.
- Version 7.2.5.2 is affected.
- Version 7.3.1.2 is affected.
- Version 7.2.8 is affected.
- Version 7.6.0 is affected.
- Version 7.4.2 is affected.
- Version 7.2.8.1 is affected.
- Version 7.0.6.3 is affected.
- Version 7.4.2.1 is affected.
- Version 7.2.9 is affected.
- Version 7.0.7 is affected.
- Version 7.7.0 is affected.
- Version 7.4.2.2 is affected.
- Version 7.2.10 is affected.
- Version 7.6.1 is affected.
- Version 7.4.2.3 is affected.
- Version 7.0.8 is affected.
- Version 7.6.2 is affected.
- Version 7.7.10 is affected.
- Version 7.2.10.1 is affected.
- Version 7.0.8.1 is affected.
- Version 7.6.2.1 is affected.
- Version 7.2.10.2 is affected.
- Version 7.7.10.1 is affected.
- Version 7.4.2.4 is affected.
- Version 7.4.3 is affected.
- Version 7.6.3 is affected.
- Version 7.7.11 is affected.
- Version 7.6.4 is affected.
- Version 10.0.0 is affected.
- Version 7.4.4 is affected.
- Version 7.4.5 is affected.
- Version 7.0.9 is affected.
- Version 7.2.11 is affected.
- Version 7.7.12 is affected.
- Version 7.6.5 is affected.
- Version 7.4.6 is affected.
- Version 10.0.1 is affected.
- Version 7.4.7 is affected.