CVE-2026-20343

Cisco Secure Firewall Management Center Software Information Disclosure and Disk Denial of Service Vulnerability

Severity
High 7.5
CVSS 3.1
Remote · no auth what this means
Exploited
Not listed
EPSS
0.004
36.9th percentile
Discovered by
Vendor
Vendor-published field
Published
Sep 16, 2026
Assigned by cisco

Description

A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authentication. An attacker could exploit this vulnerability by repeatedly invoking the API. A successful exploit could allow the attacker to download sensitive files that should be restricted and consume disk space so the device could become unresponsive, causing a DoS condition.

Weakness: CWE-306

Affected products

Vendor Product Category Matched by
Cisco Cisco Secure Firewall Management Center Check your version Network & Security Management cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco Secure Firewall Management Center (FMC)

Vendor advisory

cisco-sa-fmc-mulivulns-4PsnFwvx

Cisco Secure Firewall Management Center Software Vulnerabilities

Cisco’s rating: Critical (advisory CVSS 9.1) · Published Sep 16, 2026

Bug IDs: CSCwu16954 , CSCwu24501 , CSCwu27275 , CSCwu36643 , CSCwu42586

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?