CVE-2026-20106 Details
Description
A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition requiring a manual reboot. This vulnerability is due to trusting user input without validation. An attacker could exploit this vulnerability by sending crafted packets to the Remote Access SSL VPN server. A successful exploit could allow the attacker to cause the device to stop responding, resulting in a DoS condition.
A denial-of-service vulnerability has been identified in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. This vulnerability allows an unauthenticated, remote attacker to exhaust device memory, leading to a DoS condition that requires a manual reboot. The issue arises from insufficient validation of user input, enabling attackers to send crafted packets to the VPN server and disrupt normal device operations. Additionally, this vulnerability affects the management HTTP server and Mobile User Security (MUS) features if they are enabled.
Cisco has released software updates to address this vulnerability. Instructions for upgrading Cisco Secure FTD devices are available in the Cisco Secure FMC upgrade guide. For Cisco Secure Firewall ASA, consult the Cisco Secure Firewall ASA Upgrade Guide and use the Cisco Software Checker tool to identify the first fixed release.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-m9sx6MbC | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco adaptive security appliance software | >= 9.12.1, < 9.16.4.85 >= 9.17.1, < 9.18.4.66 >= 9.19.1, < 9.20.4 >= 9.22.1.1, < 9.22.2.4 >= 9.23.1, < 9.23.1.7 |
CPE
Remediation
| |
| cisco secure firewall threat defense | >= 6.4.0, < 7.0.9 >= 7.1.0, < 7.2.11 >= 7.3.0, < 7.4.3 >= 7.6.0, < 7.6.4 >= 7.7.0, < 7.7.11 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | Initial Analysis | [email protected] |
| Mar 4, 2026 | New CVE Received | [email protected] |