Junglewise Threat Intelligence

CVE-2026-20100: Cisco Secure Firewall ASA and FTD Remote Access SSL VPN denial of service

CVE-2026-20100 · Severity: high · CVSS 7.7 · Published 2026-03-04

Technologies: Cisco Secure Firewall Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software. Vendors: Cisco.

Executive brief

Cisco's Secure Firewall ASA and FTD devices protect corporate networks by acting as firewalls and threat defense appliances. A vulnerability in the Remote Access SSL VPN feature could allow authenticated attackers to crash these devices, causing a complete denial of service until manual reboot. This impacts organizations relying on VPN access for remote work and business continuity.

Technical details

The vulnerability exists in the LUA interpreter component of the Remote Access SSL VPN feature, which fails to properly validate user-supplied input before processing it. An authenticated, remote attacker with a valid VPN connection can send crafted HTTP packets to exploit this flaw, triggering an unhandled condition that causes the device to reload unexpectedly. The attack vector is network-accessible and requires an authenticated VPN session. Cisco has released software patches to address this issue; no workarounds are available.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance Software Multiple versions (see vendor advisory for specifics)
  • Cisco Secure Firewall Threat Defense Software Multiple versions (see vendor advisory for specifics)

Timeline

  • 2026-03-04: disclosed: Publicly disclosed by Cisco

References

Related threats