Improper Neutralization in Cisco Secure Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20330
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to failure to ensure structured messages or data are well-formed and meet security properties in Cisco Secure Firewall ASA Software, Cisco Secure FTD Software, and Cisco Secure FMC Software when accessed over a network. A remote user can access the software over a network to compromise confidentiality, integrity, and availability.
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2026-20330
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47, 9.24.1.26