Executive brief
Cisco Secure Firewall products (ASA, FTD, and FMC) contain multiple critical vulnerabilities in input validation and data handling discovered during an internal security review. These flaws could allow authenticated attackers with network access to cause denial of service, bypass security controls, or gain unauthorized access to protected systems. The vulnerabilities affect firewall appliances and management systems widely deployed to protect corporate networks.
Technical details
CVE-2026-20330 addresses improper neutralization issues grouped under CWE-707, affecting how structured messages and data are validated before processing. The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Secure Firewall Threat Defense (FTD) Software, and Secure Firewall Management Center (FMC) Software. Attack vectors include network-accessible services requiring low privileges. The advisory indicates multiple related vulnerabilities were discovered during internal testing; two related CVE IDs within this group (CWE-284 class) are known to be actively exploited in the wild. Cisco has released patched software versions to address these issues, with no workarounds available.
Affected products
- Cisco Secure Firewall Adaptive Security Appliance Software <UNKNOWN>
- Cisco Secure Firewall Threat Defense Software <UNKNOWN>
- Cisco Secure Firewall Management Center Software <UNKNOWN>
Timeline
- 2026-09-16: disclosed: Cisco security advisory published
- exploited: Two related vulnerabilities in this advisory group (CWE-284 class) are known to be actively exploited