PT-2026-93868 · Cisco · Secure Ftd+1
CVE-2026-76420
·
Published
2026-09-16
·
Updated
2026-09-17
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Secure FMC Software (affected versions not specified)
Description
An issue exists in the internal configuration of the Apache JServ Protocol (AJP) connector. This is caused by the incorrect initialization of encryption parameters for the AJP connector during boot time. An unauthenticated remote attacker could exploit this by sending crafted packets to the AJP connector to impersonate a peer device. Successful exploitation allows the attacker to execute commands as root and gain full control over the FMC REST APIs. This issue is only exploitable if the valid sftunnel connection between Cisco Secure FMC Software and Cisco Secure FTD Software is down.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Secure Fmc
Secure Ftd