Improper access control in Cisco Secure Firewall Threat Defense (FTD) and Cisco Secure Firewall Adaptive Security Appliance (ASA) - CVE-2026-20121

 

Improper access control in Cisco Secure Firewall Threat Defense (FTD) and Cisco Secure Firewall Adaptive Security Appliance (ASA) - CVE-2026-20121

Published: September 18, 2026


Vulnerability identifier: #VU150902
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20121
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to a logic error in populating group access control policies (ACPs) with Object Group Search (OGS) configured. A remote attacker can bypass access controls and reach devices in protected networks.


Affected software

Cisco Secure Firewall Threat Defense (FTD)
Cisco Secure Firewall Adaptive Security Appliance (ASA)

How to mitigate CVE-2026-20121

Install updates from vendor's website.

Cisco Secure Firewall Threat Defense (FTD) - addressed in versions 7.6.4, 7.6.6, 7.7.13, 9.22.2.32, 9.22.3, 9.22.3.5, 9.22.3.26, 9.23.1.26, 9.23.1.32, 9.23.1.47, 9.24.1, 9.24.1.5, 9.24.1.9, 9.24.1.11, 9.24.1.26, 10.0.0, 10.0.2
Cisco Secure Firewall Adaptive Security Appliance (ASA) - addressed in versions 7.6.4, 7.6.6, 7.7.13, 9.22.2.32, 9.22.3, 9.22.3.5, 9.22.3.26, 9.23.1.26, 9.23.1.32, 9.23.1.47, 9.24.1, 9.24.1.5, 9.24.1.9, 9.24.1.11, 9.24.1.26, 10.0.0, 10.0.2

External References

Related Security Bulletins