ZeroHour

CVE-2026-20331

mass1

Protection Mechanism Failure in Cisco Secure ASA, FTD, and Firewall Management Center

CVSS 3.1
9.6 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-20331 tracks multiple internally discovered vulnerabilities in Cisco Secure Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software, all classified as failures of protection mechanisms (CWE-693) and addressed through a software hardening release. Cisco has not published detailed technical specifics, but the CVSS 3.1 vector indicates an attacker needs only adjacent network access, with no privileges or user interaction, and that impact crosses security boundaries (scope changed) with high confidentiality and integrity effects plus low availability impact. This is consistent with a bypass of security controls on a firewall/VPN platform, where successful exploitation could let an attacker defeat protections the appliance is meant to enforce. Any organization running affected ASA, FTD, or FMC software is in scope, and FMC operators should note that the management center can propagate exposure across large fleets of managed FTD devices. As of now there is no known exploitation, no public proof of concept, and the issue is not on the CISA KEV list.

What to do: Consult Cisco's advisory for the hardening release and upgrade ASA, FTD, and FMC to the fixed releases it specifies for your software train, since the bundle covers multiple internally found issues. In the interim, limit adjacent-network reachability to device management interfaces and review VPN and management-plane access controls. Because the flaws were found internally and details are sparse, monitor Cisco PSIRT for updated indicators and remediation guidance.

Affected
Cisco Secure Adaptive Security Appliance (ASA) Software
Cisco Secure Firewall Threat Defense (FTD) Software
Cisco Secure Firewall Management Center (FMC) Software
Estimated exposure
masslikely hundreds of thousands of deployed ASA/FTD appliances plus FMC-managed fleets worldwide — Cisco ASA/FTD is one of the most widely deployed enterprise firewall and remote-access VPN platforms, and public internet scans (e.g., Shodan/Censys) have historically shown hundreds of thousands of exposed ASA/FTD devices, with FMC…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20331 are related to the failure of protection mechanisms issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-693.

Weakness
CWE-693
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.