Junglewise Threat Intelligence

CVE-2026-20249: Cisco Secure Firewall IKEv2 certificate authentication denial of service

CVE-2026-20249 · Severity: high · CVSS 8.6 · Published 2026-09-16

Executive brief

Cisco Secure Firewall ASA and FTD devices used to protect enterprise networks can be disrupted by an unauthenticated remote attacker sending a crafted certificate during VPN connection setup. An attacker can crash the IKEv2 process without authentication, causing the firewall to reload and interrupting all network traffic protected by the device until it recovers.

Technical details

A logic error in the IKEv2 certificate authentication phase allows unauthenticated, remote attackers to cause denial of service. The vulnerability exists in both Cisco Secure Firewall ASA and Threat Defense (FTD) software when IKEv2 VPN with certificate authentication is enabled. An attacker can exploit this by crafting a malicious certificate and attempting to establish an IKEv2 connection, triggering an unhandled condition that crashes the IKEv2 process and causes the device to reload. No user interaction or authentication is required. Cisco has released software updates for all affected versions, and no workarounds are available.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance Software 9.16 and earlier (fixed in 9.16.4.103), 9.18.x (fixed in 9.18.4.94), 9.20.x (fixed in 9.20.4.49), 9.22.x (fixed in 9.22.3.26), 9.23.x (fixed in 9.23.1.47), 9.24.x (fixed in 9.24.1.26)
  • Cisco Secure Firewall Threat Defense Software 7.0 and earlier (fixed in 7.0.10), 7.2.x (fixed in 7.2.12), 7.4.x (fixed in 7.4.8), 7.6.x (fixed in 7.6.6), 7.7.x (fixed in 7.7.13), 10.0.x (fixed in 10.0.2), 10.1.x (fixed in 10.1.0)

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Fixed software releases available

References

Related threats