Improper access control in Cisco Secure Firewall Threat Defense (FTD) and Cisco Secure Firewall Adaptive Security Appliance (ASA) - CVE-2026-20120
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to a logic error in populating group access control policies (ACPs) with Object Group Search (OGS) configured. A remote attacker can bypass access controls and reach devices in protected networks.
Affected software
Cisco Secure Firewall Adaptive Security Appliance (ASA)
How to mitigate CVE-2026-20120
Cisco Secure Firewall Adaptive Security Appliance (ASA) - addressed in versions 7.6.4, 7.6.6, 7.7.13, 9.22.2.32, 9.22.3, 9.22.3.5, 9.22.3.26, 9.23.1.26, 9.23.1.32, 9.23.1.47, 9.24.1, 9.24.1.5, 9.24.1.9, 9.24.1.11, 9.24.1.26, 10.0.0, 10.0.2