Junglewise Threat Intelligence

CVE-2026-20014: Cisco Secure Firewall ASA and FTD IKEv2 denial of service

CVE-2026-20014 · Severity: high · CVSS 7.7 · Published 2026-03-04

Technologies: Cisco Secure Firewall ASA Software, Cisco Secure Firewall Threat Defense Software. Vendors: Cisco.

Executive brief

Cisco Secure Firewall ASA and FTD are network appliances that protect enterprise networks by filtering traffic and providing VPN connectivity. A flaw in the IKEv2 VPN protocol feature allows attackers with valid VPN credentials to send specially crafted packets that exhaust device memory, forcing a restart and disrupting VPN services for all connected users across the network.

Technical details

CVE-2026-20014 is a denial-of-service vulnerability in the IKEv2 packet processing logic of Cisco Secure Firewall ASA and FTD software, caused by improper handling that allows memory exhaustion (CWE-401 resource exhaustion). The vulnerability requires an authenticated remote attacker with valid VPN credentials to send crafted IKEv2 packets to an affected device; IKEv2 must be enabled on at least one interface. Successful exploitation exhausts device memory and triggers a forced reload, temporarily making the firewall unavailable and impacting all downstream network services. Cisco has released patches addressing this vulnerability; no workarounds are available.

Affected products

  • Cisco Secure Firewall ASA Software <UNKNOWN>
  • Cisco Secure Firewall Threat Defense Software <UNKNOWN>

Timeline

  • 2026-03-04: disclosed: Cisco Security Advisory published

References

Related threats