CVE-2026-20154
Cisco ASA and FTD logging denial of service lets remote attackers exhaust CPU (CVE-2026-20154)
Unauthenticated remote attackers can cause high CPU and denial of service on Cisco ASA and FTD firewalls by flooding a device with TCP SYN packets. Apply Cisco's logging rate-limit workaround and monitor for fixed releases.
What happened
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software have a flaw in the rate-limiting process for syslog message 419002. An unauthenticated, remote attacker can exploit it by sending a flood of TCP SYN packets to an affected device. The device can then spend excessive CPU handling the logging generated by those packets, resulting in performance degradation or a denial of service.
The vulnerability has a CVSS 3.1 score of 8.6, with high availability impact. No privileges or user interaction are required, and attack complexity is low. Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability described in the advisory.
Who is affected
Cisco lists the following software as affected: ASA Software versions 9.16.1, 9.16.1.28, 9.16.2, 9.16.2.3, 9.16.2.7, 9.16.2.11, 9.16.2.13 and 9.16.2.14; FTD Software versions 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3 and 7.2.0. These are firewall software platforms. Because the flaw is reachable over the network without authentication, devices with interfaces exposed to untrusted traffic are the main concern.
What to do now
- Apply Cisco's workaround now. For ASA Software, enter global configuration mode and add:
logging rate-limit 100 1 message 419002. For FTD Software, use Secure Firewall Management Center (FMC) > Devices > Platform Settings > Rate Limit > Syslog Level and deploy the appropriate policies. - Monitor Cisco's advisory for fixed releases applicable to your software train. The data reviewed for this page does not list specific fixed version numbers, so confirm those against the vendor advisory before upgrading.
How to detect it
Watch for sustained high CPU utilization or performance degradation on ASA and FTD devices, and for an elevated rate of TCP SYN traffic to those devices. Cisco has not published separate indicators of compromise in the advisory reviewed here.
Beyond the patch
Beyond applying the workaround, this is a reminder that unauthenticated, network-reachable flaws in firewalls are an exposure problem before they are a patching problem. Virtual CISO Services (vCISO) can help you inventory firewall interfaces and reduce the attack surface that such floods can reach.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 9.16.1 9.16.1.28 9.16.2 9.16.2.3 9.16.2.7 9.16.2.11 9.16.2.13 9.16.2.14 | No fixed version listed yet |
| Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |