CVE-2026-20332
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
In plain language
AI Act nowThis is a critical security flaw in Cisco firewall software with a public attack tool available; affected businesses should act urgently, although a fixed version is not yet known.
Improper access control vulnerabilities in Cisco Secure Adaptive Security Appliance (ASA) Software, Secure Firewall Threat Defense (FTD) Software, and Secure Firewall Management Center (FMC) Software may let a logged-in attacker bypass intended permissions and compromise connected systems.
What to do now
- Identify whether you run Cisco Secure Adaptive Security Appliance (ASA) Software, Secure Firewall Threat Defense (FTD) Software, or Secure Firewall Management Center (FMC) Software.
- Ask your Cisco support contact or IT provider whether your installed release is covered by CVE-2026-20332; no fixed version has been published in the available information.
- Restrict management access to trusted administrators and networks until Cisco provides remediation.
- Review administrator accounts and recent firewall or management-setting changes for anything unexpected.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20332 and every CVE in our database. Create a free account — no credit card required.
Create Free Account