Junglewise Threat Intelligence

CVE-2026-20335: Cisco Secure Firewall ASA calculation error in security-critical context

CVE-2026-20335 · Severity: high · CVSS 8.1 · Published 2026-09-16

Executive brief

Cisco Secure Firewall Adaptive Security Appliance (ASA) is a widely-deployed network appliance that protects corporate networks by monitoring and filtering traffic. A calculation error in security-critical operations allows authenticated attackers to bypass access controls or cause service disruptions, potentially compromising network security and availability.

Technical details

CVE-2026-20335 is a calculation vulnerability (CWE-682) affecting Cisco Secure Firewall ASA Software that generates incorrect results used in security-critical decisions or resource management. The vulnerability requires low privileges and network access, and can be exploited without user interaction. An authenticated attacker can leverage this calculation error to achieve high impact on confidentiality, integrity, and availability. Cisco released software updates to remediate the issue; no workarounds are available.

Affected products

  • Cisco Secure Firewall ASA Software Multiple affected versions; see vendor advisory for patched releases

Timeline

  • 2026-09-16: disclosed

References

Related threats