Improper Check or Handling of Exceptional Conditions in Cisco Secure Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20329

 

Improper Check or Handling of Exceptional Conditions in Cisco Secure Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20329

Published: September 17, 2026


Vulnerability identifier: #VU150747
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20329
CWE-ID: CWE-703
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper handling of exceptional conditions in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.


Affected software

Cisco Secure Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2026-20329

Install security update from vendor's website.

Cisco Secure Firewall Threat Defense (FTD) - addressed in versions 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2, 10.1.0
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47, 9.24.1.26

External References

Related Security Bulletins