Missing Release of Resource after Effective Lifetime in Cisco Secure Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20250
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in DTLS message handling when processing certain DTLS messages. A remote attacker can send a crafted stream of DTLS traffic to cause a denial of service.
DTLS flow offload must be enabled on Cisco Secure Firewall 3100 Series or 4200 Series devices.
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2026-20250
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.22.2.32, 9.23.1.32, 9.24.1.5