Memory leak in Cisco Secure Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20222
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the EIGRP implementation when handling EIGRP update messages. A remote attacker can send crafted EIGRP updates at a high rate to trigger a memory leak and cause a denial of service.
Only devices with EIGRP enabled are affected.
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2026-20222
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.20.4.49, 9.22.3.26, 9.23.1.47, 9.24.1.26