CVE Tools

CVE-2026-20331

Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure Vulnerabilities

Published: Sep 16, 2026Updated: Sep 18, 2026 Sources: CVE List NVDCWE-693

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.   The vulnerabilities tracked by CVE-2026-20331 are related to the failure of protection mechanisms issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-693.

In plain language

AI Act now

This is a critical weakness in Cisco firewall and firewall-management software; small businesses using it should treat it as urgent because public attack code is available.

Executive summary

CVE-2026-20331 is a critical adjacent-network protection-mechanism failure affecting Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software.

If affected, business impact
Security-control bypassSensitive data exposureUnauthorized configuration changesNetwork service disruption

What to do now

  1. Check whether you run Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software, or Cisco Secure Firewall Management Center Software.
  2. Ask your Cisco support contact or managed IT provider whether your installed release is affected by CVE-2026-20331.
  3. No fixed version has been published in the available findings; obtain Cisco's current remediation guidance before making upgrade changes.
  4. Until guidance is available, limit access to the management and firewall interfaces to only required internal networks and approved administrators.
May need vendor / contractor work

CVSS Vector Breakdown

AV:AAC:LPR:NUI:NS:CC:HI:HA:L
Exploitability
AV:AAttack Vector
Adjacent
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:LAvailability
Low

Weaknesses

Affected Products

Exploitability

0 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

References

1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-20331 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows