Cisco Secure Firewall Management Center sftunnel Flaw (CVE-2026-20324) Explained Overview CVE-2026-20324 is a critical vulnerability in the sftunnel component of Cisco Secure Firewall Management Center (FMC). Cisco rates the flaw at CVSS 9.9. Successful exploitation lets an unauthenticated remote attacker execute arbitrary code with root privileges on the affected system. The issue was disclosed as part of a September 16, 2026 wave of fixes for Cisco Secure Firewall products....