Executive brief
Cisco Secure Firewall ASA and FTD are network appliances that protect enterprise networks by filtering traffic and providing VPN connectivity. A flaw in the IKEv2 VPN protocol feature allows attackers with valid VPN credentials to send specially crafted packets that exhaust device memory, forcing a restart and disrupting VPN services for all connected users across the network.
Technical details
CVE-2026-20014 is a denial-of-service vulnerability in the IKEv2 packet processing logic of Cisco Secure Firewall ASA and FTD software, caused by improper handling that allows memory exhaustion (CWE-401 resource exhaustion). The vulnerability requires an authenticated remote attacker with valid VPN credentials to send crafted IKEv2 packets to an affected device; IKEv2 must be enabled on at least one interface. Successful exploitation exhausts device memory and triggers a forced reload, temporarily making the firewall unavailable and impacting all downstream network services. Cisco has released patches addressing this vulnerability; no workarounds are available.
Affected products
- Cisco Secure Firewall ASA Software <UNKNOWN>
- Cisco Secure Firewall Threat Defense Software <UNKNOWN>
Timeline
- 2026-03-04: disclosed: Cisco Security Advisory published