CVE-2026-20329
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20329 are related to issues concerning improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.
In plain language
AI Act nowThis is a critical flaw in Cisco firewall software; businesses using the affected products should treat it as urgent because a public exploit is available and no fix information is available.
CVE-2026-20329 is a CVSS 9.9 exceptional-conditions handling vulnerability (CWE-703) in Cisco firewall products that may enable a low-privileged attacker to compromise confidentiality, integrity, and availability across security scope boundaries.
What to do now
- Inventory every installation of cisco secure firewall adaptive security appliance (asa) software, cisco secure firewall threat defense (ftd) software, and cisco secure firewall management center (fmc), including its installed version and who can log in.
- Restrict management access immediately to named administrators on trusted internal networks or a private management connection; remove unnecessary accounts and review administrator permissions.
- No fixed version has been announced in the available findings; check Cisco's advisory for CVE-2026-20329 and apply the exact fixed release as soon as Cisco publishes it.
- Review firewall and management-system logs for unexpected administrator logins, configuration exports or changes, new accounts, and unexplained restarts.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20329 and every CVE in our database. Create a free account — no credit card required.
Create Free Account