ZeroHour

CVE-2026-20329

mass

Multiple Exception-Handling Flaws in Cisco Secure ASA, FTD and Firewall Management Center

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-20329 tracks multiple vulnerabilities in Cisco Secure Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software, all involving improper handling of exceptional conditions (CWE-703 pillar) and discovered during a comprehensive internal Cisco security review. Cisco is addressing them through a software hardening release rather than describing individual exploitation paths, so the exact trigger conditions per flaw are not itemized in the available data. The CVSS 9.9 (critical) score with AV:N/AC:L/PR:L/UI:N/S:C indicates the flaws are reachable over the network, without user interaction, by an attacker who already holds valid low-privileged credentials (for example, a VPN user or low-privileged management account), and that successful exploitation can affect resources beyond the vulnerable component with high impact to confidentiality, integrity, and availability. Any organization running Cisco ASA, FTD, or FMC is potentially affected, with edge firewalls (ASA/FTD) representing the largest exposed population. Exploitation status: no entry in CISA KEV, no public proof-of-concept, and no known in-the-wild exploitation as of this analysis.

What to do: Review the Cisco PSIRT advisory for CVE-2026-20329 to identify affected releases for your ASA, FTD, and FMC deployments and upgrade to the software hardening release it specifies. Because the CVSS vector indicates a low-privileged authenticated attacker is required, enforce multi-factor authentication on VPN and management access, rotate VPN user and administrative credentials, and restrict management interface exposure to trusted networks. The CVE description is generic, so monitor Cisco PSIRT for expanded detail and updated fixed-version lists.

Affected
Cisco Secure Adaptive Security Appliance (ASA) Software
Cisco Secure Firewall Threat Defense (FTD) Software
Cisco Secure Firewall Management Center (FMC) Software
Estimated exposure
masshundreds of thousands of devices (Cisco ASA/FTD is among the most widely deployed edge firewall platforms, with ~100k+ instances visible in public internet… — Estimated from Cisco ASA/FTD's very large global installed base as a default enterprise/edge firewall and internet-wide scan data showing on the order of 100,000+ publicly visible Cisco ASA/FTD instances; FMC deployments are typically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20329 are related to issues concerning improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.

Weakness
CWE-703
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.