Executive brief
Cisco Secure Firewall appliances (ASA, Threat Defense, and Management Center) contain multiple improper access control vulnerabilities discovered during an internal security review. These flaws allow authenticated attackers to bypass authorization checks and gain unauthorized access to firewall functionality, potentially compromising network security controls and enabling data exfiltration or lateral movement within protected networks.
Technical details
CVE-2026-20332 represents a set of improper access control vulnerabilities (CWE-284) grouped under a single CVE identifier by Cisco as part of a comprehensive hardening release. The vulnerability requires authentication (PR:L per CVSS vector) and allows an attacker to gain high-impact unauthorized access with network reachability (AV:N, AC:L). An authenticated attacker can bypass authorization mechanisms to access restricted firewall functions or administrative features. Cisco has released software updates to address these issues; no workarounds are available.
Affected products
- Cisco Secure Firewall ASA Software Multiple versions vulnerable; see fixed software section
- Cisco Secure Firewall Threat Defense Software Multiple versions vulnerable; see fixed software section
- Cisco Secure Firewall Management Center Software Multiple versions vulnerable; see fixed software section
Timeline
- 2026-09-16: disclosed: Advisory published by Cisco