External risk intelligence

Apache JServ Protocol Connector Vulnerability Allows Remote Device Impersonation in Cisco Secure FMC Software

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-76420

The AJP connector is typically used for internal communication between Cisco Secure FMC and FTD components via a dedicated tunnel (sftunnel). Public exposure of this specific inter-device management protocol is uncommon, and the exploit condition requires the established sftunnel connection to be down, further limiting the scenarios where this interface would be reachable.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Cisco Secure FMC Software's Apache JServ Protocol (AJP) connector could allow an unauthenticated attacker to impersonate a peer device. This is due to incorrect initialization of encryption parameters at boot time, potentially allowing an attacker to execute commands as root and gain full control over FMC REST APIs if a secure tunnel connection is down.

  • Unauthenticated impersonation via AJP connector.
  • Affects Cisco Secure FMC Software's management APIs.
  • Confirm relevance and exposure for management systems.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could impersonate a peer device by sending specially crafted packets to the Apache JServ Protocol (AJP) connector, provided the secure tunnel between Cisco Secure FMC and FTD software is not active. This vulnerability arises from incorrect initialization of encryption parameters during the connector's startup. A successful exploit allows the attacker to execute commands as root, gaining complete control over the FMC REST APIs.

  • No authentication required to initiate attack.
  • Exploited by sending crafted packets to AJP connector.
  • Results in root command execution and API control.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated, remote attacker could impersonate a peer device, potentially executing commands as root and gaining full control over FMC REST APIs when the AJP connector's encryption parameters are not initialized correctly at boot time and the secure tunnel between Cisco Secure FMC and FTD software is down.

  • System data and device control.
  • Sending crafted packets to the AJP connector.
  • Full control of FMC REST APIs.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Cisco Secure FMC Software's AJP connector requires immediate attention from teams managing Cisco security infrastructure. The first step is to identify all instances of affected Cisco FMC software, assess their exposure, and determine business criticality. Subsequently, coordinate with the relevant platform or security operations teams to plan and execute remediation, considering any dependencies and potential operational impacts.

  • Own by infrastructure and platform teams.
  • Verify AJP connector exposure and reachability.
  • Plan for remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Apache JServ Protocol (AJP) connector in Cisco Secure FMC Software?

The AJP connector is a component within Cisco Secure FMC Software used for specialized communication between the Firepower Management Center (FMC) and Cisco Secure Firepower Threat Defense (FTD) devices. It typically facilitates internal data exchange and management through an encrypted tunnel known as sftunnel, which ensures that security policies and device state information are synchronized between these central management platforms and the firewalls they control.

What does CWE-285 mean for CVE-2026-76420?

CWE-285 refers to Improper Authorization. In the context of this vulnerability, it means the system fails to correctly verify the identity of a device or user before granting access to sensitive functions. Because the AJP connector initializes encryption parameters incorrectly at boot, it cannot properly validate incoming requests, allowing an unauthenticated party to bypass security checks and impersonate a trusted peer device.

How does an attacker trigger this AJP connector vulnerability?

An attacker triggers this flaw by sending specially crafted network packets to the AJP connector. Importantly, the vulnerability does not trigger if the secure sftunnel connection between the FMC and FTD software is functioning normally. The attack condition requires that the sftunnel is currently down, which creates the opening for the service to accept unauthorized traffic.

Is this FMC vulnerability an internet-facing risk?

According to Halo Surface Signal, this risk is unlikely to be internet-facing. The AJP connector is designed for internal communication between management and security components. Because successful exploitation requires both access to this specific internal protocol and a disrupted sftunnel connection, the practical reach for an external attacker is significantly constrained in most network environments.

What should I do if I manage Cisco Secure FMC systems?

Begin by identifying all deployed instances of the affected Cisco Secure FMC software in your infrastructure. Assess the network reachability of these systems to verify if the AJP connector is accessible from unintended network segments. Once you understand your current footprint, coordinate with your security or infrastructure teams to review official guidance and plan for necessary software updates or configuration changes.

References