ZeroHour

CVE-2026-20336

mass1· 1 read

Improper Resource Lifetime Control in Cisco Secure ASA, FTD, and Firewall Management Center

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-20336 is an improper control of a resource through its lifetime (CWE-664) in Cisco Secure Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software, discovered internally during a comprehensive Cisco security review and addressed in a software hardening release. The flaw is exploitable from an adjacent network (CVSS AV:A) without privileges or user interaction, and successful exploitation could yield high-impact confidentiality, integrity, and availability compromise on the affected appliance or management platform. Cisco ASA and FTD are among the most widely deployed enterprise firewall platforms, and FMC is the central manager for FTD fleets, so most organizations running these products are in scope. There is currently no public proof-of-concept, no known in-the-wild exploitation, and the issue is not on CISA's Known Exploited Vulnerabilities catalog.

What to do: Check Cisco's PSIRT advisory for CVE-2026-20336 to identify the hardening release covering your ASA, FTD, and FMC version trains, and upgrade accordingly. Because the attack vector is adjacent (AV:A), restrict management and VPN-facing interfaces to trusted network segments and limit L2/L3 adjacency to untrusted devices in the meantime. ASA/FTD/FMC bundles frequently ship related fixes, so apply the full hardening release rather than cherry-picking individual CVEs.

Affected
Cisco Secure Adaptive Security Appliance (ASA) Software
Cisco Secure Firewall Threat Defense (FTD) Software
Cisco Secure Firewall Management Center (FMC) Software
Estimated exposure
mass≈ hundreds of thousands of ASA/FTD appliances and FMC-managed deployments worldwide — Cisco ASA/FTD are among the most widely deployed enterprise firewall and VPN platforms, with public internet scans historically showing well over 100,000 exposed ASA/FTD endpoints and FMC broadly used to manage them, though exact affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20336 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.

Weakness
CWE-664
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.