ZeroHour

CVE-2026-20333

mass

Incorrect Comparison Conditions in Cisco Secure Firewall ASA, FTD, and FMC Software

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-20333 tracks incorrect comparison conditions (CWE-697) in Cisco Secure Adaptive Security Appliance (ASA) Software, Secure Firewall Threat Defense (FTD) Software, and Secure Firewall Management Center (FMC) Software, discovered by Cisco during an internal security review and addressed in a software hardening release. Because the CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N, an attacker needs only network reachability to the affected interface and valid low-privileged credentials to trigger the flaw, with no user interaction required. Successful exploitation of the faulty comparison logic could bypass checks enforced by the affected software and, per the 8.8 score, has potential for high impact on confidentiality, integrity, and availability. Any organization running Cisco ASA, FTD, or FMC is potentially affected, though the specific vulnerable release trains must be confirmed against the Cisco advisory. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known.

What to do: Consult the Cisco PSIRT advisory for CVE-2026-20333 to confirm affected releases and upgrade ASA, FTD, and FMC to the fixed hardening release it specifies. In the interim, restrict management interfaces (FMC web UI, FTD/ASA management) to trusted admin networks and enforce strong authentication, since exploitation requires valid low-privileged credentials. Monitor Cisco PSIRT for updates, as this hardening advisory covers multiple internally discovered flaws and may be revised.

Affected
Cisco Secure Adaptive Security Appliance (ASA) Software
Cisco Secure Firewall Threat Defense (FTD) Software
Cisco Secure Firewall Management Center (FMC) Software
Estimated exposure
mass≈100,000+ devices (public internet scans routinely show on the order of 100k+ Cisco ASA/FTD appliances; the installed base is in the millions) — Cisco ASA/FTD is one of the most widely deployed enterprise edge firewall platforms and public scan data consistently shows hundreds of thousands of internet-facing appliances, though the subset running the vulnerable releases is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20333 are related to incorrect comparison conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-697.

Weakness
CWE-697
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.