Junglewise Threat Intelligence

CVE-2026-20120: Cisco Secure Firewall ASA/FTD access control bypass in OGS

CVE-2026-20120 · Severity: medium · CVSS 5.8 · Published 2026-09-16

Executive brief

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) are widely deployed firewalls used to protect corporate networks and enforce access policies. A logic error in their Object Group Search (OGS) feature for access control lists could allow an attacker to send traffic that should be blocked, bypassing firewall rules and reaching protected internal systems without authentication.

Technical details

This vulnerability stems from a logic error in how the ASA and FTD populate group access control policies (ACPs) when Object Group Search (OGS) is configured. The issue is classified as an improper access control (CWE-284). An unauthenticated, remote attacker can exploit this by sending traffic crafted to bypass the ACL checks, requiring only network reachability to the firewall device. A successful exploit allows complete circumvention of configured access controls, enabling an attacker to reach systems and networks that should be protected. Cisco has released patched software versions; no workarounds are available.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance 9.22, 9.23, 9.24 (with OGS configured)
  • Cisco Secure Firewall Threat Defense Multiple releases with OGS configured

Timeline

  • 2026-09-16: disclosed: Cisco Security Advisory published

References

Related threats