CVE-2026-20343
Cisco Secure Firewall Management Center Software Information Disclosure and Disk Denial of Service Vulnerability
Description
A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authentication. An attacker could exploit this vulnerability by repeatedly invoking the API. A successful exploit could allow the attacker to download sensitive files that should be restricted and consume disk space so the device could become unresponsive, causing a DoS condition.
Weakness: CWE-306
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Secure Firewall Management Center Check your version | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco Secure Firewall Management Center (FMC)
Vendor advisory
cisco-sa-fmc-mulivulns-4PsnFwvx
Cisco Secure Firewall Management Center Software Vulnerabilities
Cisco’s rating: Critical (advisory CVSS 9.1) · Published Sep 16, 2026
Bug IDs: CSCwu16954 , CSCwu24501 , CSCwu27275 , CSCwu36643 , CSCwu42586
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from