Database/Control plane, storage & DevOps
Cisco Secure Firewall Management Center: unauthenticated HTTP request yields root on the appliance
Impact
An unauthenticated attacker who can reach the FMC web interface gets root on the underlying operating system, which means full control of the box that writes policy to every managed firewall in the fleet. In a GPU datacenter that terminates tenant traffic behind Cisco firewalls, that is the device deciding which tenants can reach the management VLAN, the storage network and the fabric; root on it lets an attacker rewrite those rules and hide the change. CISA has this in KEV and Talos reports ongoing exploitation, so treat any exposed FMC as potentially already compromised rather than merely vulnerable. Recovery is not just patching - credentials, policy state and any certificates held on the appliance have to be assumed exposed.
Who can reach it
Anyone who can send HTTP requests to the FMC web interface. No authentication and no user interaction required, so an FMC reachable from a tenant network or the internet is directly exploitable.
What to do
Apply the fixed release named in the Cisco advisory; the record does not list version numbers, so take them from the advisory itself. An FMC upgrade reboots the appliance, so managed firewalls run on last-pushed policy during the window - no dataplane outage, but no policy changes either. Because this is under active exploitation, restrict the web interface to the management network immediately and hunt for compromise before assuming a patch is sufficient.
References
Related entries
- Kestra: suffix-match auth bypass on /configs gives unauthenticated workflow execution as rootCVE-2026-49869 · Kestra AuthenticationFilter (suffix match on the /configs path whitelist)Critical
- Linux crypto driver for Marvell OCTEON TX: The scatter-gather cleanup path in the Marvell OCTEON TX crypto driver usesCVE-2026-74280 · Linux crypto driver for Marvell OCTEON TXCritical
- Linux VXLAN driver (neighbour hardware address read in route_shortcircuit): `route_shortcircuit()` reads a neighbour'sCVE-2026-74475 · Linux VXLAN driver (neighbour hardware address read in route_shortcircuit)Critical
- SonicWall SMA1000: pre-auth SSRF via an unintended alternate access path in the Work Place interfaceCVE-2026-83548 · SonicWall SMA1000 appliance (Work Place interface, alternate access path)Critical
- Kubeflow Pipelines frontend (/_proxy/ route, proxy-middleware.ts): The pipelines frontend hands any unauthenticatedNCVD-2026-042-kubeflow-pipelines-frontend-prox · Kubeflow Pipelines frontend (/_proxy/ route, proxy-middleware.ts)Critical
- HTCondor (condor_credd): condor_credd can be told to create or write files as root outsideCVE-2021-25311 · HTCondor (condor_credd)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.