CVE-2026-76420

CRITICALCVSS 9/10

Last modified

CVE-2026-76420 is a critical-severity vulnerability rated 9/10 on the CVSS scale. A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to incorrect initialization of encryption parameters for the AJP connector at boot time. An attacker could exploit this vulnerability by sending crafted packets to the AJP connector.

Description

A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to incorrect initialization of encryption parameters for the AJP connector at boot time. An attacker could exploit this vulnerability by sending crafted packets to the AJP connector. A successful exploit could allow the attacker to execute commands as root and gain full control over the FMC REST APIs on the affected device. Note: This vulnerability can be exploited only if the valid sftunnel connection between Cisco Secure FMC Software and Cisco Secure FTD Software is down.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
CiscoCisco Secure Firewall Management Center (FMC)7.0.0; 7.0.0.1; 7.0.1; 7.0.1.1; 7.0.2; 7.2.0; 7.0.2.1; 7.0.3; 7.2.0.1; 7.0.4; 7.2.1; 7.0.5; 7.3.0; 7.2.2; 7.3.1; 7.2.3; 7.2.3.1; 7.2.4; 7.0.6; 7.2.4.1; 7.2.5; 7.3.1.1; 7.4.0; 7.0.6.1; 7.2.5.1; 7.4.1; 7.2.6; 7.4.1.1; 7.0.6.2; 7.2.7; 7.2.5.2; 7.3.1.2; 7.2.8; 7.6.0; 7.4.2; 7.2.8.1; 7.0.6.3; 7.4.2.1; 7.2.9; 7.0.7; 7.7.0; 7.4.2.2; 7.2.10; 7.6.1; 7.4.2.3; 7.0.8; 7.6.2; 7.7.10; 7.2.10.1; 7.0.8.1; 7.6.2.1; 7.2.10.2; 7.7.10.1; 7.4.2.4; 7.4.3; 7.6.3; 7.7.11; 7.6.4; 10.0.0; 7.4.4; 7.4.5; 7.0.9; 7.2.11; 7.7.12; 7.6.5; 7.4.6; 10.0.1; 7.4.7

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-76420?
A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to incorrect initialization of encryption parameters for the AJP connector at boot time. An attacker could exploit this vulnerability by sending crafted packets to the AJP connector. A successful exploit could allow the attacker to execute commands as root and gain full control over the FMC REST APIs on the affected device. Note: This vulnerability can be exploited only if the valid sftunnel connection between Cisco Secure FMC Software and Cisco Secure FTD Software is down.
How severe is CVE-2026-76420?
CVE-2026-76420 has a CVSS score of 9/10 (CRITICAL severity).
How do I fix CVE-2026-76420?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-76420?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST