Missing Release of Resource after Effective Lifetime in Cisco Secure Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20250

 

Missing Release of Resource after Effective Lifetime in Cisco Secure Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20250

Published: September 17, 2026


Vulnerability identifier: #VU150756
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20250
CWE-ID: CWE-772
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource management in DTLS message handling when processing certain DTLS messages. A remote attacker can send a crafted stream of DTLS traffic to cause a denial of service.

DTLS flow offload must be enabled on Cisco Secure Firewall 3100 Series or 4200 Series devices.


Affected software

Cisco Secure Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2026-20250

Install security update from vendor's website.

Cisco Secure Firewall Threat Defense (FTD) - addressed in versions 7.6.6, 7.7.13, 10.0.2
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.22.2.32, 9.23.1.32, 9.24.1.5

External References

Related Security Bulletins