Junglewise Threat Intelligence

CVE-2026-20329: Cisco Secure Firewall improper exception handling and input validation

CVE-2026-20329 · Severity: critical · CVSS 9.9 · Published 2026-09-16

Executive brief

Cisco Secure Firewall products—which protect enterprise networks by filtering and monitoring traffic—contain multiple critical vulnerabilities in exception handling, input validation, and access control. An authenticated attacker can exploit these flaws to bypass authentication, gain unauthorized access, crash the firewall, or compromise confidentiality and integrity of network traffic. Two vulnerabilities are currently being exploited in the wild.

Technical details

This advisory groups eight distinct vulnerabilities across Cisco Secure Firewall ASA, Threat Defense, and Management Center software, categorized by root cause (CWE-703 improper exception handling, CWE-707 improper input validation, CWE-284 access control flaws, and others). The vulnerabilities were discovered during Cisco's internal security review. The primary attack vector is network-based with low attack complexity; exploitation requires low privileges (authentication) and produces high impact on confidentiality, integrity, and availability. Two vulnerabilities in the access control class (CWE-284) affecting the Management Center are confirmed actively exploited; these include static credential and authentication bypass issues. Cisco has released patched software versions; no workarounds are available.

Affected products

  • Cisco Secure Firewall ASA Software Multiple versions; see vendor advisory for specific fixed releases
  • Cisco Secure Firewall Threat Defense Software Multiple versions; see vendor advisory for specific fixed releases
  • Cisco Secure Firewall Management Center Software Multiple versions; see vendor advisory for specific fixed releases

Timeline

  • 2026-09-16: disclosed: Cisco security advisory published
  • exploited: Two vulnerabilities in access control class (CWE-284) confirmed actively exploited in the wild

References

Related threats