Junglewise Threat Intelligence

CVE-2026-20064: Cisco Secure Firewall Threat Defense authenticated DoS via CLI input validation

CVE-2026-20064 · Severity: medium · CVSS 6.5 · Published 2026-03-04

Executive brief

Cisco Secure Firewall Threat Defense (FTD) is a network security appliance that protects enterprise networks by inspecting and blocking malicious traffic. A vulnerability in its command-line interface (CLI) allows an authenticated user with low-level privileges to crash the device by submitting specially crafted commands, causing a temporary service outage and preventing network traffic inspection until the device restarts.

Technical details

CVE-2026-20064 is an authenticated denial-of-service vulnerability in Cisco Secure FTD Software's CLI feature, caused by insufficient input validation of user-supplied command arguments (CWE-88). An attacker with valid low-privileged local authentication can exploit this by submitting crafted input to a specific CLI command, triggering an unexpected device reload. The attack requires local access and valid credentials but no user interaction or elevated privileges. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco Secure Firewall Threat Defense

Timeline

  • 2026-03-04: disclosed

References

Related threats