Junglewise Threat Intelligence

CVE-2026-20039: Cisco Secure Firewall ASA and FTD VPN web server denial of service

CVE-2026-20039 · Severity: high · CVSS 8.6 · Published 2026-03-04

Executive brief

Cisco's Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) products include a VPN web server used to manage remote access connections. A memory management defect allows an unauthenticated attacker to send crafted HTTP requests that exhaust resources and force the device to reload, causing an outage of the firewall and any VPNs it manages.

Technical details

This vulnerability is a denial of service flaw caused by ineffective memory management in the VPN web server component (CWE-244). The vulnerability affects devices with IKEv2 Remote Access VPN with client services or SSL VPN configured. An unauthenticated remote attacker can exploit this by sending a large number of crafted HTTP requests to the affected device's web server; no authentication or special privileges are required. A successful exploit causes the device to reload, resulting in a denial of service condition. Cisco has released fixed software versions to address this issue; no workarounds are available.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) <UNKNOWN>
  • Cisco Secure Firewall Threat Defense (FTD) <UNKNOWN>

Timeline

  • 2026-03-04: disclosed

References

Related threats