Junglewise Threat Intelligence

CVE-2026-20331: Cisco Secure Firewall protection mechanism failure

CVE-2026-20331 · Severity: critical · CVSS 9.6 · Published 2026-09-16

Technologies: Cisco Secure Firewall Management Center Software, Cisco Secure Firewall ASA Software, Cisco Secure Firewall Threat Defense Software. Vendors: Cisco.

Executive brief

Cisco's Secure Firewall suite (ASA, Threat Defense, and Management Center) contains multiple critical vulnerabilities discovered during an internal security review and grouped under a single CVE. These failures in protection mechanisms could allow authenticated attackers to bypass firewall controls, escalate privileges, or compromise the appliance, directly undermining the security devices that organizations rely on to protect their networks.

Technical details

CVE-2026-20331 tracks a protection mechanism failure (CWE-693) in Cisco Secure Firewall ASA, Threat Defense (FTD), and Management Center (FMC) software. The underlying issue involves improper use of a protection mechanism that fails to defend against directed attacks. Multiple vulnerabilities are grouped under related CWE categories including improper access control (CWE-284), incorrect comparisons in security-relevant contexts (CWE-697), and other control flow and validation issues. The advisory indicates at least two related vulnerabilities are actively exploited in the wild. Attack requires authentication (PR:L per CVSS vector) and is network-reachable. Cisco has released software updates to address these issues; no workarounds are available.

Affected products

  • Cisco Secure Firewall ASA Software
  • Cisco Secure Firewall Threat Defense Software
  • Cisco Secure Firewall Management Center Software

Timeline

  • 2026-09-16: disclosed: Public disclosure of CVE-2026-20331 and related hardening release
  • 2026: exploited: Two related vulnerabilities actively exploited in the wild at time of disclosure
  • 2026-09: patched: Software updates released to address vulnerabilities

References

Related threats