CVE-2026-20135
Cisco Secure Firewall Threat Defense TLS 1.3 denial of service (CVE-2026-20135)
Cisco Secure Firewall Threat Defense has a high-severity TLS 1.3 denial-of-service flaw. An unauthenticated remote attacker can crash the LINA process and reload a vulnerable device. Fixes are available; patch or temporarily disable TLS 1.3.
What happened
A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software allows an unauthenticated, remote attacker to cause an affected device to reload, creating a denial of service. The cause is improper buffer management during a TLS 1.3 connection. By sending a crafted TLS 1.3 packet to a TLS 1.3-enabled listening socket, an attacker can crash the LINA process, and the reload can happen before or after authentication of the connection.
Cisco notes that TLS 1.3 connections include both data traffic and user-management traffic. The vulnerability has a CVSS 3.1 score of 8.6, high severity, with a network attack vector, low complexity, no privileges and no user interaction; the impact is entirely to availability.
Cisco PSIRT states it is not aware of any public announcements or malicious use of the vulnerability described in this advisory.
Who is affected
Cisco Secure Firewall Threat Defense (FTD) Software is the affected product, commonly used on Cisco firewall platforms at the network edge or in data centres. The releases Cisco lists as affected are 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3 and 7.2.0. If you run one of these releases and have TLS 1.3 enabled on any listening socket, treat the device as vulnerable. No other product versions are listed as affected here.
What to do now
- Confirm whether your FTD software release appears in the affected list above.
- Apply the fixed release. Cisco indicates fixes are available; the specific fixed versions are in the Cisco advisory linked with this page.
- If you cannot patch immediately, apply the mitigation Cisco describes: temporarily remove TLS 1.3 from the device configuration. Use Cisco Secure FMC Software and a FlexConfig object to set the minimum and maximum TLS version to TLS 1.2.
- Treat this as a temporary mitigation, not a replacement for patching. Cisco tested the approach in a test environment, but it may reduce functionality or performance; validate it in your own environment before applying.
- Monitor affected devices for unexpected reloads or LINA process crashes while the mitigation is in place.
How to detect it
Monitor affected FTD devices for unexpected reloads or LINA process crashes, especially on appliances with TLS 1.3 enabled on internet-facing or user-facing services. The advisory does not list specific indicators of compromise; the main observable effect is the availability impact itself. Reviewing which listening sockets have TLS 1.3 enabled will help you understand the exposed attack surface until a patch or mitigation is applied.
Beyond the patch
Beyond patching, the practical risk here is exposure: an unauthenticated, network-reachable trigger means the issue only matters where a TLS 1.3-enabled socket is reachable by someone who can send it a crafted packet. Virtual CISO Services can help you identify and reduce that exposed footprint. Because Cisco FTD is a vendor product running across your estate, tracking its lifecycle and patching cadence through Supply Chain Defense & Third-Party Risk helps you manage the next advisory before it becomes an emergency.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |