Type conversion in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20249
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a logic error in the IKEv2 certificate authentication feature when processing a crafted certificate during IKEv2 VPN connection setup. A remote attacker can attempt to establish an IKEv2 VPN connection with a crafted certificate to cause a denial of service.
Only devices with the IKEv2 VPN feature enabled and configured for certificate authentication are affected.
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2026-20249
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.103, 9.18.4.94, 9.20.4.34, 9.22.3.5, 9.23.1.47, 9.24.1.11, 10.0.2