Skip to content

CVE-2026-20249

Cisco ASA and FTD IKEv2 certificate authentication denial of service (CVE-2026-20249)

High 8.6 Vendor: Cisco Published

Unauthenticated remote attackers can crash IKEv2 VPN services on affected Cisco ASA and FTD appliances by sending a crafted certificate during connection setup. Cisco has published a fix; no workaround is available.

What happened

An unauthenticated remote attacker can exploit this vulnerability by attempting to establish an IKEv2 VPN connection using a crafted certificate. A logic error during the certificate authentication phase causes the IKEv2 process on the affected Cisco ASA or FTD software to crash, which reloads the device and creates a denial of service condition.

Attack complexity is low, no privileges or user interaction are required, and the vulnerability is reachable over the network. The impact is limited to availability; confidentiality and integrity are not affected. Cisco PSIRT states that it is not aware of any public announcements or malicious use of this vulnerability.

Who is affected

This affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software versions 9.16.1, 9.16.1.28, 9.16.2, 9.16.2.3, 9.16.2.7, 9.16.2.11, 9.16.2.13 and 9.16.2.14, and Cisco Secure Firewall Threat Defense (FTD) Software versions 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3 and 7.2.0. These are firewall and VPN appliances; organisations running these releases with IKEv2 certificate authentication enabled should review the Cisco advisory for the correct fixed release for their version.

What to do now

  1. Apply Cisco's fix. Cisco has published a fix; consult the Cisco security advisory for the fixed release that applies to your version.
  2. There is no workaround that addresses this vulnerability.
  3. If you cannot apply the fix immediately, restrict exposure of IKEv2 endpoints to trusted peers and monitor affected appliances for unexpected reloads or IKEv2 process crashes.
  4. Review the Cisco security advisory for any additional guidance.

How to detect it

Monitor affected Cisco ASA or FTD appliances for unexpected reloads, particularly where IKEv2 certificate authentication is enabled. No separate indicators of compromise are listed in the advisory.

Beyond the patch

This is an unauthenticated, network-reachable denial-of-service flaw in a core firewall and VPN appliance. Patching is the priority, but this also illustrates why knowing which VPN services are exposed and monitoring for unexpected reloads matters. Spirity's Virtual CISO Services can help identify exposed services before a denial-of-service attempt reaches them, and Managed Detection and Response can watch for the IKEv2 process crash or reload activity that follows.

Affected and fixed versions

ProductAffectedFixed in
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software9.16.1
9.16.1.28
9.16.2
9.16.2.3
9.16.2.7
9.16.2.11
9.16.2.13
9.16.2.14
No fixed version listed yet
Cisco Secure Firewall Threat Defense (FTD) Software7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.