DIRAS TAKE
Urgent: this is a remote, unauthenticated root-capable flaw with no patch available for affected 7.x releases; immediately restrict access to the AJP connector and follow the vendor's mitigation guidance.
What is CVE-2026-76420?
An unauthenticated remote attacker can send crafted AJP packets to Cisco Secure Firewall Management Center (FMC) to execute commands as root and gain full control of the FMC REST APIs, tracked as CVE-2026-76420. The flaw affects multiple 7.x FMC releases including 7.0.0 through 7.0.4 and 7.2.0 / 7.2.0.1 as listed by the vendor. Exploitation requires network access to the AJP connector and only works when the sftunnel connection between FMC and Secure FTD is down; no authenticated account or user interaction is required.
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Cisco Cisco Secure Firewall Management Center (FMC) are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.0.0 | |
| 7.x | 7.0.0.1 | |
| 7.x | 7.0.1 | |
| 7.x | 7.0.1.1 | |
| 7.x | 7.0.2 | |
| 7.x | 7.2.0 | |
| 7.x | 7.0.2.1 | |
| 7.x | 7.0.3 | |
| 7.x | 7.2.0.1 | |
| 7.x | 7.0.4 |
Is CVE-2026-76420 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-76420
- Isolate or block network access to the AJP connector/service on FMC from untrusted networks.
- Ensure the sftunnel connection between FMC and Secure FTD is healthy and monitored to reduce exposure to this vector.
- Follow Cisco's vendor guidance and advisories for configuration mitigations and future patches.
- Enable enhanced logging and monitor FMC REST API and system logs for unusual activity or unauthorized commands.
Frequently asked questions
Is CVE-2026-76420 being actively exploited?
There are no public reports of active exploitation of CVE-2026-76420 as of 2026-09-30.
Which Cisco Secure FMC versions are affected by CVE-2026-76420?
Cisco Secure FMC releases in the 7.x branch are affected, including the listed versions from 7.0.0 up through 7.0.4 and 7.2.0 / 7.2.0.1 as provided by the vendor.
Is there a patch for CVE-2026-76420?
No patch is listed for the affected releases as of 2026-09-30; follow Cisco's advisory and apply recommended mitigations until a fix is available.
Does CVE-2026-76420 require authentication?
No, the issue can be triggered by an unauthenticated remote attacker with network access to the AJP connector, but exploitation depends on the sftunnel connection being down.
References
- nvd.nist.gov/vuln/detail/CVE-2026-76420
- cve.org/CVERecord?id=CVE-2026-76420
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc2-multivulns-HXgcqRG
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026