OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-76420

CRITICAL · CVSS 9 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the Apache JServ Protocol (AJP) connector of Cisco Secure FMC Software, allowing unauthenticated remote attackers to impersonate peer devices by exploiting improperly initialized encryption parameters. Successful exploitation can lead to root command execution and full control over the FMC REST APIs, posing significant risks to network security. Organizations using Cisco Secure FMC and Secure FTD Software should prioritize immediate remediation, especially if they rely on sftunnel connections.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76420
Severity
CRITICAL
CVSS
9
EPSS
0.38%
Cisco Apache

Original NVD Description

A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to incorrect initialization of encryption parameters for the AJP connector at boot time. An attacker could exploit this vulnerability by sending crafted packets to the AJP connector. A successful exploit could allow the attacker to execute commands as root and gain full control over the FMC REST APIs on the affected device. Note: This vulnerability can be exploited only if the valid sftunnel connection between Cisco Secure FMC Software and Cisco Secure FTD Software is down.