ZeroHour

CVE-2026-20335

large

Incorrect Calculation Flaws in Cisco Secure ASA, Firewall Threat Defense, and FMC

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-20335 covers one or more incorrect calculation vulnerabilities (CWE-682) in Cisco Secure Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software, discovered internally during a Cisco security review rather than through external reports. The CVSS vector indicates the flaw is reachable over the network without authentication or user interaction, but exploitation requires elevated conditions (AC:H), and the high impact ratings suggest successful attacks could compromise confidentiality, integrity, and availability of the affected device. Organizations running Cisco ASA, FTD, or FMC in any deployment—particularly internet-facing VPN and firewall appliances—are in scope for remediation. As of this analysis, Cisco has addressed the issue in a software hardening release, and there are no reports of exploitation, no public proof-of-concept, and the CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Consult the Cisco PSIRT advisory for this hardening release and upgrade ASA, FTD, and FMC to the fixed versions it specifies, since exact affected ranges are not listed in the summary data. In the interim, limit exposure of ASA/FTD management and VPN interfaces to the internet and verify no anomalous device behavior. Monitor Cisco PSIRT for updates, as the vague CWE-682 grouping and high-attack-complexity score suggest details may be refined over time.

Affected
Cisco Secure Adaptive Security Appliance (ASA) Software
Cisco Secure Firewall Threat Defense (FTD) Software
Cisco Secure Firewall Management Center (FMC) Software
Estimated exposure
largehundreds of thousands of deployed ASA/FTD/FMC instances, with likely tens of thousands internet-exposed — Cisco ASA/FTD is among the most widely deployed enterprise firewall and VPN platforms, and public internet scans (e.g., Shodan) have historically shown on the order of hundreds of thousands of exposed Cisco ASA/FTD devices, with FMC…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20335 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682.

Weakness
CWE-682
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.