Executive brief
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) are widely deployed firewalls used to protect corporate networks and enforce access policies. A logic error in their Object Group Search (OGS) feature for access control lists could allow an attacker to send traffic that should be blocked, bypassing firewall rules and reaching protected internal systems without authentication.
Technical details
This vulnerability stems from a logic error in how the ASA and FTD populate group access control policies (ACPs) when Object Group Search (OGS) is configured. The issue is classified as an improper access control (CWE-284). An unauthenticated, remote attacker can exploit this by sending traffic crafted to bypass the ACL checks, requiring only network reachability to the firewall device. A successful exploit allows complete circumvention of configured access controls, enabling an attacker to reach systems and networks that should be protected. Cisco has released patched software versions; no workarounds are available.
Affected products
- Cisco Secure Firewall Adaptive Security Appliance 9.22, 9.23, 9.24 (with OGS configured)
- Cisco Secure Firewall Threat Defense Multiple releases with OGS configured
Timeline
- 2026-09-16: disclosed: Cisco Security Advisory published