PT-2026-93868 · Cisco · Secure Ftd+1

CVE-2026-76420

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Secure FMC Software (affected versions not specified)
Description An issue exists in the internal configuration of the Apache JServ Protocol (AJP) connector. This is caused by the incorrect initialization of encryption parameters for the AJP connector during boot time. An unauthenticated remote attacker could exploit this by sending crafted packets to the AJP connector to impersonate a peer device. Successful exploitation allows the attacker to execute commands as root and gain full control over the FMC REST APIs. This issue is only exploitable if the valid sftunnel connection between Cisco Secure FMC Software and Cisco Secure FTD Software is down.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15160
CVE-2026-76420

Affected Products

Secure Fmc
Secure Ftd