SB20260917252 - Multiple vulnerabilities in Cisco ASA and Cisco FTD
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 vulnerabilities.
1) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-20329)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper handling of exceptional conditions in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.
2) Improper Neutralization (CVE-ID: CVE-2026-20330)
CWE-ID: CWE-707 - Improper Neutralization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to failure to ensure structured messages or data are well-formed and meet security properties in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.
3) Protection mechanism failure (CVE-ID: CVE-2026-20331)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to incorrect use of a protection mechanism in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.
4) Improper access control (CVE-ID: CVE-2026-20332)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper access control in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.
5) Incorrect Comparison (CVE-ID: CVE-2026-20333)
CWE-ID: CWE-697 - Incorrect Comparison
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to incorrect comparison in a security-relevant context in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.
6) Improper Adherence to Coding Standards (CVE-ID: CVE-2026-20334)
CWE-ID: CWE-710 - Improper Adherence to Coding Standards
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper adherence to coding standards in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.
7) Incorrect calculation (CVE-ID: CVE-2026-20335)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to an incorrect calculation used in security-critical decisions or resource management in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.
8) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-20336)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper control of a resource through its lifetime in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.