ZeroHour

CVE-2026-20332

mass1

Improper Access Control in Cisco ASA, FTD, and Firewall Management Center

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-20332 covers improper access control issues (CWE-284) in Cisco Secure Adaptive Security Appliance (ASA), Secure Firewall Threat Defense (FTD), and Secure Firewall Management Center (FMC) software, discovered during Cisco's internal security review and addressed in a dedicated software hardening release. A remote attacker who already holds a low-privileged account or session (CVSS PR:L over the network, no user interaction) can trigger the flaw. Because the attack scope is changed and confidentiality, integrity, and availability impacts are all rated high, successful exploitation crosses a security boundary, giving the attacker high-impact control over the device or access to data it protects. Any organization running affected ASA, FTD, or FMC releases is exposed, though exploitation requires valid low-privileged credentials. No public proof-of-concept or known exploitation exists; the flaw was internally discovered by Cisco and is not yet in CISA's Known Exploited Vulnerabilities catalog.

What to do: Upgrade ASA, FTD, and FMC devices to the Cisco software hardening release cited in the Cisco PSIRT advisory (specific fixed version numbers should be confirmed there). Until patched, restrict management-plane and VPN access to trusted users and networks, and audit low-privileged accounts and their permissions for access-boundary gaps. Monitor Cisco PSIRT for updates, as exploitation requires a valid low-privileged credential and no public exploit is currently known.

Affected
Cisco Secure Adaptive Security Appliance (ASA) Software
Cisco Secure Firewall Threat Defense (FTD) Software
Cisco Secure Firewall Management Center (FMC) Software
Estimated exposure
masshundreds of thousands of internet-exposed Cisco ASA/FTD devices; total deployed base likely in the millions — Cisco ASA/FTD is among the most widely deployed enterprise edge firewall/VPN platforms, and public internet-wide scans have historically indexed hundreds of thousands of ASA/FTD appliances with exposed management or VPN interfaces.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Cisco patches dozens of critical flaws in FMC, ISE and Nexus Dashboard, including ISE bugs and an authentication bypass already exploited in the wild.

Cisco released patches for dozens of critical-severity CVEs in Secure Firewall Management Center, Identity Services Engine and Nexus Dashboard. ISE updates cover 20 CVEs including 12 critical ones; three publicly disclosed flaws (CVE-2026-20282, CVE-2026-20283, CVE-2026-20284) enable SQL injection, data tampering and command execution but require administrative access. FMC patches fix 18 CVEs, eight critical, several shared with ASA and FTD, where CVE-2026-20079 and CVE-2026-20316 have been exploited since August. Cisco also warned of a critical-severity ISE authentication bypass exploited in the wild as a zero-day.