CVE-2026-20330
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20330 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.
In plain language
AI Act nowThis is a critical security flaw in Cisco Secure Firewall ASA, FTD, and FMC software with a public exploit available, so affected businesses should act now even though Cisco has not published a fix.
CVE-2026-20330 is a CVSS 9.9 improper-neutralization issue (CWE-707) in Cisco Secure Firewall ASA, FTD, and FMC software that a logged-in attacker may exploit to compromise confidentiality, integrity, and availability across a security boundary.
What to do now
- Check whether you run cisco secure firewall adaptive security appliance (asa) software, cisco secure firewall threat defense (ftd) software, or cisco secure firewall management center (fmc), and record each installed version.
- Treat every deployed version as potentially affected until Cisco publishes affected-version details; no fixed version is currently available.
- Restrict administrative access to trusted staff and networks, review administrator accounts, and remove any accounts that are no longer needed.
- Ask your Cisco support contact for the hardening release or mitigation guidance for CVE-2026-20330, then schedule its deployment promptly.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20330 and every CVE in our database. Create a free account — no credit card required.
Create Free Account