ZeroHour

CVE-2026-20330

mass

Improper Neutralization Flaws in Cisco Secure ASA, FTD and FMC Software

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-20330 tracks a set of improper neutralization issues (CWE-707) that Cisco's engineering team discovered during an internal security review of its Secure Firewall lineup and addressed in a software hardening release. The flaws are remotely exploitable over the network with low attack complexity, but require an attacker to hold low-privileged credentials on the affected product, with no user interaction required. The scope-changed, high-impact CVSS vector indicates an attacker who exploits the flaw could achieve significant confidentiality, integrity, and availability impact beyond the initial security context, typically meaning control of the firewall or management platform. Organizations running Cisco Secure Adaptive Security Appliance (ASA) Software, Secure Firewall Threat Defense (FTD) Software, or Secure Firewall Management Center (FMC) Software are affected. As of now there is no evidence of exploitation in the wild, no public proof-of-concept, and the issue is not in CISA's Known Exploited Vulnerabilities catalog.

What to do: Review Cisco's security advisory for CVE-2026-20330 and upgrade ASA, FTD, and FMC to the fixed releases in the hardening release cited by Cisco. Because exploitation requires low-privileged credentials, audit for weak or default accounts, enforce multi-factor authentication on VPN and management access, and restrict exposure of management interfaces to trusted networks. Monitor Cisco PSIRT channels for updated fixed-version details, as the source data does not specify exact version numbers.

Affected
Cisco Secure Adaptive Security Appliance (ASA) Software
Cisco Secure Firewall Threat Defense (FTD) Software
Cisco Secure Firewall Management Center (FMC) Software
Estimated exposure
masshundreds of thousands of deployed Cisco ASA/FTD appliances plus FMC management servers worldwide (public scans consistently show 100k+ internet-exposed ASA/FTD… — Cisco ASA/FTD is one of the most widely deployed enterprise firewall and remote-access VPN platforms, and internet-wide scans routinely enumerate on the order of 100,000 or more exposed ASA/FTD VPN and web management endpoints, with FMC…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20330 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.

Weakness
CWE-707
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.