CVE Tools

CVE-2026-20333

Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Incorrect Comparison Vulnerabilities

Published: Sep 16, 2026Updated: Sep 18, 2026 Sources: CVE List NVDCWE-697

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20333 are related to incorrect comparison conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-697.

In plain language

AI Act now

A serious flaw affects Cisco Secure Firewall ASA, FTD, and FMC software; businesses using these network-reachable systems should act now because a public exploit is available.

Executive summary

CVE-2026-20333 is a CVSS 8.8 incorrect-comparison vulnerability (CWE-697) in Cisco Secure Firewall ASA Software, FTD Software, and FMC that a low-privileged network attacker may use to compromise confidentiality, integrity, and availability.

If affected, business impact
Firewall administration compromiseNetwork security disruptionSensitive data exposureService outages

What to do now

  1. Check whether you run Cisco Secure Firewall ASA Software, Cisco Secure Firewall Threat Defense Software, or Cisco Secure Firewall Management Center Software, and identify every internet-reachable management system.
  2. No fixed version has been published in the provided findings; ask Cisco or your managed IT provider for the vendor's remediation release and deployment timeline.
  3. Until a fix is available, limit management access to trusted administrator networks, remove unnecessary low-level accounts, and review administrator activity for unexpected changes.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

0 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

References

1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-20333 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows