Junglewise Threat Intelligence

CVE-2026-20336: Cisco Secure Firewall software resource lifecycle vulnerability

CVE-2026-20336 · Severity: high · CVSS 8.8 · Published 2026-09-16

Executive brief

Cisco's Secure Firewall products (ASA, Threat Defense, and Management Center) contain a flaw involving improper control of system resources throughout their lifetime—such as uninitialized variables or null pointer dereferences. An authenticated attacker with network access could exploit this to cause service disruption or potentially gain unauthorized access to security appliance functionality, undermining the protection these firewalls provide.

Technical details

CVE-2026-20336 addresses improper control of a resource through its lifetime (CWE-664), covering uninitialized variables, null pointers, and resource lifecycle issues. This vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA), Secure Firewall Threat Defense (FTD), and Secure Firewall Management Center (FMC) software. The vulnerability requires network access and local privilege context to exploit; it was discovered during internal security review. An attacker can achieve denial of service or information disclosure depending on the specific resource mismanagement instance. Cisco has released fixed software versions, and no workarounds are available.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance Multiple releases (see vendor advisory for fixed releases)
  • Cisco Secure Firewall Threat Defense Multiple releases (see vendor advisory for fixed releases)
  • Cisco Secure Firewall Management Center Multiple releases (see vendor advisory for fixed releases)

Timeline

  • 2026-09-16: disclosed: Cisco security advisory published
  • 2026-09-16: patched: Fixed software releases made available by Cisco

References

Related threats