Improper Neutralization of Argument Delimiters in a Command in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20016
Published: March 10, 2026
Vulnerability identifier: #VU123678
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20016
CWE-ID: CWE-88
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation in the Cisco FXOS Software CLI feature. A local privileged user can supply specially crafted arguments for specific CLI commands and execute arbitrary code as root.
Affected software
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2026-20016
Install updates from vendor's website.
Cisco Firewall Threat Defense (FTD) - addressed in versions 7.0.9, 7.2.11, 7.4.4, 7.6.4, 7.7.11
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.89, 9.18.4.71, 9.20.4.19, 9.22.2.20, 9.23.1.26, 9.24.1
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.89, 9.18.4.71, 9.20.4.19, 9.22.2.20, 9.23.1.26, 9.24.1