Junglewise Threat Intelligence

CVE-2026-20070: Cisco Secure Firewall ASA and FTD cross-site scripting in VPN web services

CVE-2026-20070 · Severity: medium · CVSS 6.1 · Published 2026-03-04

Technologies: Cisco Secure Firewall ASA Software, Cisco Secure Firewall Threat Defense Software. Vendors: Cisco.

Executive brief

Cisco Secure Firewall ASA and FTD devices that provide VPN access to employees contain a cross-site scripting vulnerability in their web interface. An attacker could trick a user into clicking a malicious link, then execute arbitrary code in the user's browser within the context of the VPN portal, potentially stealing session tokens or credentials.

Technical details

This is a reflected cross-site scripting (XSS) vulnerability (CWE-80) in the VPN web services component due to improper validation of user-supplied input in HTTP requests. The vulnerability requires user interaction: an attacker must persuade a target to follow a crafted link to the affected device. A successful exploit allows execution of arbitrary HTML or script code in the browser context of the VPN web server. The vulnerability affects devices running vulnerable releases of ASA or FTD Software with IKEv2 Remote Access VPN (with client services) or SSL VPN features configured. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco Secure Firewall ASA Software
  • Cisco Secure Firewall Threat Defense Software

Timeline

  • 2026-03-04: disclosed

References

Related threats