Junglewise Threat Intelligence

CVE-2026-20106: Cisco Secure Firewall ASA and FTD SSL VPN denial of service

CVE-2026-20106 · Severity: medium · CVSS 5.3 · Published 2026-03-04

Executive brief

Cisco Secure Firewall appliances used to protect corporate networks include a Remote Access SSL VPN feature that is vulnerable to denial of service attacks. An unauthenticated attacker can send specially crafted packets to exhaust device memory, forcing the firewall to stop responding and require a manual reboot, thereby disrupting all protected traffic and network connectivity.

Technical details

CVE-2026-20106 is a denial of service vulnerability affecting the Remote Access SSL VPN, HTTP management server, and Mobile User Security (MUS) functionality in Cisco Secure Firewall ASA and FTD Software. The vulnerability exists due to insufficient validation of user-supplied input, allowing an unauthenticated, network-accessible attacker to send crafted packets that exhaust device memory. The flaw is rooted in improper bounds checking (CWE-120) and resource exhaustion (CWE-770). No authentication or user interaction is required; exploitation is achieved through direct network access to the SSL VPN service. A successful exploit causes the affected device to stop responding and requires a manual reboot to restore functionality. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Multiple versions (see advisory for specific fixed releases)
  • Cisco Secure Firewall Threat Defense (FTD) Software Multiple versions (see advisory for specific fixed releases)

Timeline

  • 2026-03-04: disclosed

References

Related threats