Cisco FMC CVE-2026-20324 is a Critical CVSS 9.9 vulnerability in Secure Firewall Management Center Software that Cisco says can allow an authenticated remote attacker to execute commands as root. Cisco has released fixed software and says there is no workaround. Cisco also says its Product Security Incident Response Team is not aware of public announcements or malicious use of the vulnerability.
The important boundary is that this is not an unauthenticated remote-code-execution flaw. Cisco says exploitation requires valid user credentials and an attacker who can hijack an existing sftunnel connection or act as a valid registered sftunnel peer. Administrators therefore need to check both product applicability and their exact FMC software release before selecting a fixed version.
Cisco FMC CVE-2026-20324: what is affected?
Cisco says the vulnerability affects Secure Firewall Management Center Software when sftunnel is enabled. Cisco states that sftunnel is enabled by default.
This CVE is specific to FMC. Cisco says Adaptive Security Appliance Software and Secure Firewall Threat Defense Software are not affected by CVE-2026-20324.

What does an attacker need?
The vulnerability is remotely exploitable, but Cisco does not describe it as unauthenticated. The attacker needs valid user credentials on the affected device and must be able to hijack an sftunnel connection or operate as a valid registered sftunnel peer.
Cisco attributes the flaw to incorrect permissions associated with a registered peer. A successful attacker could write a malicious file that is later executed with root privileges.
Is CVE-2026-20324 actively exploited?
Cisco has not said CVE-2026-20324 is actively exploited. In the advisory state reviewed by TPS, Cisco PSIRT says it is not aware of public announcements or malicious use of the vulnerability.
That distinction matters because a Critical severity score describes potential impact and exploitability conditions; it does not by itself prove exploitation is occurring in the wild.
Is there a workaround?
No. Cisco says there are no workarounds that address CVE-2026-20324. The supported remediation is to upgrade affected FMC software to a fixed release.
TPS is not treating disabling sftunnel as an official workaround because Cisco’s advisory does not provide that as the remediation path.
Which Cisco FMC fixed release should you install?
Cisco provides fixed software, but the correct target depends on the FMC release currently installed. Administrators should use Cisco’s Software Checker with the installed release to identify the advisory-specific First Fixed release and, where Cisco provides one, the Combined First Fixed release that resolves multiple advisories.
TPS is not publishing one guessed universal fixed version because Cisco’s remediation model is release-specific. The authoritative answer is the First Fixed or later appropriate release shown for the administrator’s current FMC branch.
Why ASA and FTD administrators should not copy this patch guidance
Cisco explicitly lists ASA Software and Secure Firewall Threat Defense Software as not affected by this specific vulnerability. That does not mean those products have no September 2026 security advisories; it means CVE-2026-20324 itself should not be generalized beyond FMC.
Does patching require compromise-response checks?
Cisco’s CVE-2026-20324 advisory establishes the affected product, exploitation prerequisites and fixed-software requirement, but it does not establish known malicious exploitation or provide a CVE-specific compromise-investigation workflow in the reviewed advisory state.
Administrators should therefore avoid importing incident-response instructions from a different actively exploited Cisco FMC vulnerability unless separate evidence shows those instructions apply.
What Cisco FMC administrators should do now
- Confirm the system is Cisco Secure Firewall Management Center rather than ASA or FTD.
- Record the exact FMC major release and installed patch level.
- Confirm whether
sftunnelis enabled; Cisco says it is enabled by default. - Use Cisco Software Checker to determine whether the installed release is affected by CVE-2026-20324.
- Identify the First Fixed or later appropriate release for the installed software branch.
- Upgrade because Cisco provides no workaround for this vulnerability.
- Do not describe the flaw internally as unauthenticated or actively exploited unless Cisco’s advisory state changes.
Bottom line
Cisco FMC CVE-2026-20324 requires fixed software, but exposure is more specific than a generic ‘remote Critical RCE’ description suggests. The vulnerability affects FMC with sftunnel enabled, requires valid credentials plus the stated peer or connection position, and can result in root-level code execution.
Cisco says there is no workaround and has released fixes. Administrators should resolve the exact First Fixed release against their installed FMC version rather than relying on a generic version number. Cisco currently reports no known malicious use.
Verification note
TPS reviewed Cisco’s PSIRT advisory for CVE-2026-20324, including affected-product statements, attack prerequisites, impact, workaround status, fixed-software guidance and Cisco’s current exploitation statement.
Limitations and unresolved facts
The exact First Fixed release depends on the administrator’s installed FMC branch and should be checked against Cisco’s current Software Checker. Cisco may later revise affected versions, fixed software or exploitation status. TPS did not establish generic search-volume or Google Trends evidence for this query family.