Out-of-bounds write in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20022
Published: March 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when OSPF canonicalization debug is enabled. A remote attacker on the local network can send specially crafted OSPF packets to the affected device, trigger an out-of-bounds write and perform a denial of service (DoS) attack.
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2026-20022
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.89, 9.18.4.71, 9.20.4.19, 9.22.2.20, 9.23.1.26, 9.24.1