CVE-2026-20222
Cisco ASA and FTD EIGRP denial of service lets adjacent attackers reload devices (CVE-2026-20222)
Cisco Secure Firewall ASA and FTD Software have a high-severity EIGRP denial-of-service vulnerability (CVSS 7.4). An unauthenticated adjacent attacker can cause repeated device reloads. Apply Cisco's fixed software and enable EIGRP authentication as mitigation.
What happened
An unauthenticated attacker on an adjacent network segment can send crafted EIGRP update messages at a high rate to an affected Cisco Secure Firewall ASA or Threat Defense device. The EIGRP implementation does not manage resources correctly when it handles those messages, which causes a memory leak. Over time the device exhausts memory and reloads unexpectedly. The attacker needs no credentials and no user interaction, but must already be on a network position adjacent to the device. The impact is availability only: the device goes offline until it restarts. Cisco PSIRT has said it is not aware of any public announcements or malicious use of this vulnerability.
Who is affected
Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software are firewall and threat-defence platforms commonly deployed at network perimeters, VPN termination points and internal segmentation boundaries. A device is exposed only if EIGRP is enabled. The affected releases listed by Cisco include ASA 9.19.1, 9.19.1.5, 9.19.1.9, 9.19.1.12, 9.19.1.18, 9.19.1.22, 9.20.1 and 9.20.1.5; and FTD 7.3.0, 7.3.1, 7.3.1.1, 7.3.1.2, 7.4.0, 7.4.1, 7.4.1.1 and 7.6.0.
What to do now
- Apply Cisco's fixed software for your ASA or FTD version train. Cisco states fixed software is available; do not remain on an affected release.
- If you cannot patch immediately, enable EIGRP authentication throughout the network. Cisco notes that no workarounds fully address the vulnerability, but this mitigation reduces the risk of successful exploitation. Evaluate it in your own environment before deploying, since authentication changes can affect EIGRP peering.
How to detect it
Cisco has not published indicators of compromise for this vulnerability. Because successful exploitation causes a memory leak and an eventual reload, monitor ASA and FTD devices that run EIGRP for unexpected reload events and for steadily increasing memory consumption that is not explained by normal traffic. A device that reloads repeatedly without a scheduled change should be investigated.
Beyond the patch
Beyond the patch, this is a vendor-software risk in the network's most critical path. Supply Chain Defense & Third-Party Risk helps maintain visibility of advisory and patch status across Cisco and other infrastructure vendors, so the next EIGRP-class issue is caught before it becomes an outage. Managed Detection & Response (MDR) can watch for the device instability that follows an attempt to trigger this denial of service.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 9.19.1 9.19.1.5 9.19.1.9 9.19.1.12 9.19.1.18 9.20.1 9.19.1.22 9.20.1.5 | No fixed version listed yet |
| Cisco Secure Firewall Threat Defense (FTD) Software | 7.3.0 7.3.1 7.3.1.1 7.4.0 7.4.1 7.4.1.1 7.3.1.2 7.6.0 | No fixed version listed yet |