SB20260917252 - Multiple vulnerabilities in Cisco ASA and Cisco FTD



SB20260917252 - Multiple vulnerabilities in Cisco ASA and Cisco FTD

Published: September 17, 2026

Security Bulletin ID SB20260917252
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 vulnerabilities.


1) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-20329)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper handling of exceptional conditions in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.


2) Improper Neutralization (CVE-ID: CVE-2026-20330)

CWE-ID: CWE-707 - Improper Neutralization

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to failure to ensure structured messages or data are well-formed and meet security properties in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.


3) Protection mechanism failure (CVE-ID: CVE-2026-20331)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to incorrect use of a protection mechanism in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.


4) Improper access control (CVE-ID: CVE-2026-20332)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper access control in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.


5) Incorrect Comparison (CVE-ID: CVE-2026-20333)

CWE-ID: CWE-697 - Incorrect Comparison

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to incorrect comparison in a security-relevant context in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.


6) Improper Adherence to Coding Standards (CVE-ID: CVE-2026-20334)

CWE-ID: CWE-710 - Improper Adherence to Coding Standards

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper adherence to coding standards in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.


7) Incorrect calculation (CVE-ID: CVE-2026-20335)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an incorrect calculation used in security-critical decisions or resource management in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.


8) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-20336)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper control of a resource through its lifetime in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.


Remediation

Install update from vendor's website.