Junglewise Threat Intelligence

CVE-2026-20135: Cisco Secure Firewall Threat Defense TLS 1.3 denial of service

CVE-2026-20135 · Severity: high · CVSS 8.6 · Published 2026-09-16

Executive brief

A denial of service vulnerability exists in Cisco Secure Firewall Threat Defense (FTD), a widely deployed network security appliance. An unauthenticated attacker can crash the device remotely by sending a malicious TLS 1.3 packet, forcing an unexpected reload and disrupting network operations. This can affect both management and data traffic if TLS 1.3 is enabled.

Technical details

This vulnerability stems from improper buffer management in the TLS 1.3 implementation within the LINA process. An unauthenticated, remote attacker can exploit this by sending a crafted TLS 1.3 packet to any TLS 1.3-enabled listening socket (commonly ports 443 or 8443). The vulnerability can be triggered before or after authentication, resulting in process crash and device reload. Cisco has released software patches; no workarounds exist, though administrators can temporarily disable TLS 1.3 and revert to TLS 1.2.

Affected products

  • Cisco Secure Firewall Threat Defense (FTD) See vendor advisory for affected releases

Timeline

  • 2026-09-16: disclosed

References

Related threats