Technology · Cisco
Cisco Firepower Threat Defense vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in Cisco Firepower Threat Defense: 0 in the last 7 days and 5 in the last 90 days, 3 of them critical and 3 exploited in the wild. The most recent, CVE-2026-20336, was published on 16 September 2026.
- Last 7 days
- 0
- Last 90 days
- 5
- Critical, all time
- 3
- Exploited in the wild
- 3
About Cisco Firepower Threat Defense
Cisco Firepower Threat Defense is an integrated software image providing firewall, VPN, and advanced threat protection capabilities.
Latest Cisco Firepower Threat Defense vulnerabilities
- CVE-2026-20336: Cisco Secure Firewall software resource lifecycle vulnerabilityhighCVSS 8.8EPSS 0.2%
- CVE-2026-20323: Cisco Secure FMC and FTD sftunnel authentication bypasshighCVSS 8.3EPSS 0.1%
- CVE-2026-20295: Cisco Secure FMC and FTD memory exhaustion in sftunnelhighCVSS 8.6EPSS 0.5%
- CVE-2026-20290: Cisco Secure Firewall Threat Defense SSL/TLS denial of service in Snort 2mediumCVSS 5.8EPSS 0.2%
- CVE-2026-20120: Cisco Secure Firewall ASA/FTD access control bypass in OGSmediumCVSS 5.8EPSS 0.4%
- CVE-2026-20064: Cisco Secure Firewall Threat Defense authenticated DoS via CLI input validationmediumCVSS 6.5EPSS 0.1%
- CVE-2026-20016: Cisco Secure Firewall ASA and FTD command injection in FXOS CLImediumCVSS 6EPSS 0.0%
- CVE-2026-20068: Cisco Snort 3 detection engine denial of servicemediumCVSS 5.8EPSS 0.4%
- CVE-2026-20066: Cisco Snort 3 Detection Engine denial of service in HTTP JavaScript normalizationmediumCVSS 5.8EPSS 0.4%
- CVE-2026-20065: Cisco Snort 3 Detection Engine denial of servicemediumCVSS 5.8EPSS 0.4%
- CVE-2026-20057: Cisco Snort 3 VBA decompression denial of servicemediumCVSS 5.8EPSS 0.4%
- CVE-2026-20053: Cisco Snort 3 VBA decompression denial of servicemediumCVSS 5.8EPSS 0.4%
- CVE-2026-20052: Cisco Secure Firewall Threat Defense Snort 3 memory management denial of servicemediumCVSS 5.8EPSS 0.4%
- CVE-2026-20050: Cisco Secure Firewall Threat Defense SSL decryption denial of servicemediumCVSS 6.8EPSS 0.4%
- CVE-2026-20017: Cisco Secure FTD command injection in CLImediumCVSS 6EPSS 0.2%
- CVE-2026-20007: Cisco Secure Firewall Threat Defense Snort rules bypassmediumCVSS 5.8EPSS 0.2%
- CVE-2026-20006: Cisco Secure Firewall Threat Defense TLS denial of service in Snort 3mediumCVSS 5.8EPSS 0.4%
- CVE-2026-20005: Cisco Snort 3 Detection Engine denial of service in SSL handshake parsingmediumCVSS 5.8EPSS 0.5%
- CVE-2025-20359: Cisco Snort 3 buffer under-read in HTTP MIME decodermediumCVSS 6.5EPSS 0.5%
- CVE-2025-20362: Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software…criticalexploited in the wildCVSS 6.5EPSS 87.1%
- CVE-2025-20333: A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure…criticalexploited in the wildCVSS 9.9EPSS 70.7%
- CVE-2023-20269: Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerabilitycriticalexploited in the wildCVSS 9.1
Most severe Cisco Firepower Threat Defense vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-20333: A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure…criticalexploited in the wildCVSS 9.9EPSS 70.7%
- CVE-2023-20269: Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerabilitycriticalexploited in the wildCVSS 9.1
- CVE-2025-20362: Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software…criticalexploited in the wildCVSS 6.5EPSS 87.1%
- CVE-2026-20336: Cisco Secure Firewall software resource lifecycle vulnerabilityhighCVSS 8.8EPSS 0.2%
- CVE-2026-20295: Cisco Secure FMC and FTD memory exhaustion in sftunnelhighCVSS 8.6EPSS 0.5%
- CVE-2026-20323: Cisco Secure FMC and FTD sftunnel authentication bypasshighCVSS 8.3EPSS 0.1%
- CVE-2026-20050: Cisco Secure Firewall Threat Defense SSL decryption denial of servicemediumCVSS 6.8EPSS 0.4%
- CVE-2025-20359: Cisco Snort 3 buffer under-read in HTTP MIME decodermediumCVSS 6.5EPSS 0.5%
- CVE-2026-20064: Cisco Secure Firewall Threat Defense authenticated DoS via CLI input validationmediumCVSS 6.5EPSS 0.1%
- CVE-2026-20017: Cisco Secure FTD command injection in CLImediumCVSS 6EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 5 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/firepower-threat-defense.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Cisco Firepower Threat Defense vulnerabilities", https://junglewise.ai/threats/technologies/firepower-threat-defense, 26 September 2026.