CVE-2026-20329 CVE-2026-20330 CVE-2026-20332 CVE-2026-20331 CVE-2026-20333 CVE-2026-20336 CVE-2026-20334 CVE-2026-20335
Cisco Secure Firewall ASA, FTD and FMC hardening release fixes critical and high vulnerabilities (CVE-2026-20329 through CVE-2026-20336)
Cisco has released a hardening update for ASA, FTD and FMC software addressing eight critical and high-severity vulnerabilities. No workarounds exist; Cisco reports no known exploitation. Apply the vendor release.
What happened
Cisco's internal security review of Secure Firewall ASA, Firewall Threat Defense (FTD) and Firewall Management Center (FMC) software found multiple internally discovered vulnerabilities. They are grouped under several weakness categories: improper handling of exceptional conditions, improper neutralization, improper access control, failure of protection mechanisms, incorrect comparison, incorrect calculation, improper resource lifetime management and coding standards.
The most severe entries score 9.9 and 9.6. According to the CVSS vectors, those issues can be exploited over the network or from an adjacent network; some require only low-privilege access, while one adjacent-network issue requires no authentication. Successful exploitation could lead to high impact on confidentiality, integrity and availability, and several have a changed scope, meaning compromise could extend beyond the device.
Cisco PSIRT states it is not aware of any public announcements or malicious use of these vulnerabilities. They were found internally and have not been publicly disclosed.
Who is affected
Affected software includes Cisco Secure Firewall Adaptive Security Appliance (ASA) with versions 9.16.1, 9.16.1.28, 9.16.2, 9.16.2.3, 9.16.2.7, 9.16.2.11, 9.16.2.13 and 9.16.2.14; Secure Firewall Management Center (FMC) with versions 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.2.0, 7.0.2.1 and 7.0.3; and Secure Firewall Threat Defense (FTD) with versions 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, 7.0.4 and 7.0.5. These products operate as network firewall and firewall management systems.
What to do now
- Review the Cisco advisory for the hardening release and identify the release applicable to your ASA, FTD and FMC versions.
- Plan and apply the vendor hardening release in line with your change process.
- Because Cisco states there are no workarounds, restrict access to the management interfaces of affected devices to trusted administrative networks until patching is complete.
- Verify the installed versions after updating and monitor for unexpected change.
Beyond the patch
A single vendor hardening release covering ASA, FTD and FMC is a third-party risk event: the code you depend on changed because Cisco found issues internally. Keeping an accurate inventory and triaging vendor advisories is part of the same discipline as patching. Spirity's Supply Chain Defense & Third-Party Risk service helps track vendor software risk, and our NIS2 / DORA frameworks work ties that effort to the regulatory duties many organisations now carry.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-20329 Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 9.16.1 9.16.1.28 9.16.2 9.16.2.3 9.16.2.7 9.16.2.11 9.16.2.13 9.16.2.14 | No fixed version listed yet |
| CVE-2026-20329 Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |
| CVE-2026-20329 Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.0.2.1 7.0.3 7.0.4 7.0.5 | No fixed version listed yet |
| CVE-2026-20330 Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 9.16.1 9.16.1.28 9.16.2 9.16.2.3 9.16.2.7 9.16.2.11 9.16.2.13 9.16.2.14 | No fixed version listed yet |
| CVE-2026-20330 Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |
| CVE-2026-20330 Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.0.2.1 7.0.3 7.0.4 7.0.5 | No fixed version listed yet |
| CVE-2026-20332 Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 9.16.1 9.16.1.28 9.16.2 9.16.2.3 9.16.2.7 9.16.2.11 9.16.2.13 9.16.2.14 | No fixed version listed yet |
| CVE-2026-20332 Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |
| CVE-2026-20332 Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.0.2.1 7.0.3 7.0.4 7.0.5 | No fixed version listed yet |
| CVE-2026-20331 Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 9.16.1 9.16.1.28 9.16.2 9.16.2.3 9.16.2.7 9.16.2.11 9.16.2.13 9.16.2.14 | No fixed version listed yet |
| CVE-2026-20331 Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |
| CVE-2026-20331 Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.0.2.1 7.0.3 7.0.4 7.0.5 | No fixed version listed yet |
| CVE-2026-20333 Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 9.16.1 9.16.1.28 9.16.2 9.16.2.3 9.16.2.7 9.16.2.11 9.16.2.13 9.16.2.14 | No fixed version listed yet |
| CVE-2026-20333 Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |
| CVE-2026-20333 Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.0.2.1 7.0.3 7.0.4 7.0.5 | No fixed version listed yet |
| CVE-2026-20336 Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 9.16.1 9.16.1.28 9.16.2 9.16.2.3 9.16.2.7 9.16.2.11 9.16.2.13 9.16.2.14 | No fixed version listed yet |
| CVE-2026-20336 Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |
| CVE-2026-20336 Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.0.2.1 7.0.3 7.0.4 7.0.5 | No fixed version listed yet |
| CVE-2026-20334 Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 9.16.1 9.16.1.28 9.16.2 9.16.2.3 9.16.2.7 9.16.2.11 9.16.2.13 9.16.2.14 | No fixed version listed yet |
| CVE-2026-20334 Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |
| CVE-2026-20334 Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.0.2.1 7.0.3 7.0.4 7.0.5 | No fixed version listed yet |
| CVE-2026-20335 Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 9.16.1 9.16.1.28 9.16.2 9.16.2.3 9.16.2.7 9.16.2.11 9.16.2.13 9.16.2.14 | No fixed version listed yet |
| CVE-2026-20335 Cisco Secure Firewall Management Center (FMC) | 7.0.0 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.2.0 7.0.2.1 7.0.3 | No fixed version listed yet |
| CVE-2026-20335 Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0.1 7.0.1 7.0.1.1 7.0.2 7.0.2.1 7.0.3 7.0.4 7.0.5 | No fixed version listed yet |
References
Vendor advisory
CVE
- CVE-2026-20329 — cve.org
- CVE-2026-20329 — NVD
- CVE-2026-20330 — cve.org
- CVE-2026-20330 — NVD
- CVE-2026-20332 — cve.org
- CVE-2026-20332 — NVD
- CVE-2026-20331 — cve.org
- CVE-2026-20331 — NVD
- CVE-2026-20333 — cve.org
- CVE-2026-20333 — NVD
- CVE-2026-20336 — cve.org
- CVE-2026-20336 — NVD
- CVE-2026-20334 — cve.org
- CVE-2026-20334 — NVD
- CVE-2026-20335 — cve.org
- CVE-2026-20335 — NVD