Skip to content

CVE-2026-20329 CVE-2026-20330 CVE-2026-20332 CVE-2026-20331 CVE-2026-20333 CVE-2026-20336 CVE-2026-20334 CVE-2026-20335

Cisco Secure Firewall ASA, FTD and FMC hardening release fixes critical and high vulnerabilities (CVE-2026-20329 through CVE-2026-20336)

Critical 9.9 Vendor: Cisco Published

Cisco has released a hardening update for ASA, FTD and FMC software addressing eight critical and high-severity vulnerabilities. No workarounds exist; Cisco reports no known exploitation. Apply the vendor release.

What happened

Cisco's internal security review of Secure Firewall ASA, Firewall Threat Defense (FTD) and Firewall Management Center (FMC) software found multiple internally discovered vulnerabilities. They are grouped under several weakness categories: improper handling of exceptional conditions, improper neutralization, improper access control, failure of protection mechanisms, incorrect comparison, incorrect calculation, improper resource lifetime management and coding standards.

The most severe entries score 9.9 and 9.6. According to the CVSS vectors, those issues can be exploited over the network or from an adjacent network; some require only low-privilege access, while one adjacent-network issue requires no authentication. Successful exploitation could lead to high impact on confidentiality, integrity and availability, and several have a changed scope, meaning compromise could extend beyond the device.

Cisco PSIRT states it is not aware of any public announcements or malicious use of these vulnerabilities. They were found internally and have not been publicly disclosed.

Who is affected

Affected software includes Cisco Secure Firewall Adaptive Security Appliance (ASA) with versions 9.16.1, 9.16.1.28, 9.16.2, 9.16.2.3, 9.16.2.7, 9.16.2.11, 9.16.2.13 and 9.16.2.14; Secure Firewall Management Center (FMC) with versions 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.2.0, 7.0.2.1 and 7.0.3; and Secure Firewall Threat Defense (FTD) with versions 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, 7.0.4 and 7.0.5. These products operate as network firewall and firewall management systems.

What to do now

  1. Review the Cisco advisory for the hardening release and identify the release applicable to your ASA, FTD and FMC versions.
  2. Plan and apply the vendor hardening release in line with your change process.
  3. Because Cisco states there are no workarounds, restrict access to the management interfaces of affected devices to trusted administrative networks until patching is complete.
  4. Verify the installed versions after updating and monitor for unexpected change.

Beyond the patch

A single vendor hardening release covering ASA, FTD and FMC is a third-party risk event: the code you depend on changed because Cisco found issues internally. Keeping an accurate inventory and triaging vendor advisories is part of the same discipline as patching. Spirity's Supply Chain Defense & Third-Party Risk service helps track vendor software risk, and our NIS2 / DORA frameworks work ties that effort to the regulatory duties many organisations now carry.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-20329
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
9.16.1
9.16.1.28
9.16.2
9.16.2.3
9.16.2.7
9.16.2.11
9.16.2.13
9.16.2.14
No fixed version listed yet
CVE-2026-20329
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20329
Cisco Secure Firewall Threat Defense (FTD) Software
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.0.2.1
7.0.3
7.0.4
7.0.5
No fixed version listed yet
CVE-2026-20330
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
9.16.1
9.16.1.28
9.16.2
9.16.2.3
9.16.2.7
9.16.2.11
9.16.2.13
9.16.2.14
No fixed version listed yet
CVE-2026-20330
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20330
Cisco Secure Firewall Threat Defense (FTD) Software
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.0.2.1
7.0.3
7.0.4
7.0.5
No fixed version listed yet
CVE-2026-20332
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
9.16.1
9.16.1.28
9.16.2
9.16.2.3
9.16.2.7
9.16.2.11
9.16.2.13
9.16.2.14
No fixed version listed yet
CVE-2026-20332
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20332
Cisco Secure Firewall Threat Defense (FTD) Software
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.0.2.1
7.0.3
7.0.4
7.0.5
No fixed version listed yet
CVE-2026-20331
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
9.16.1
9.16.1.28
9.16.2
9.16.2.3
9.16.2.7
9.16.2.11
9.16.2.13
9.16.2.14
No fixed version listed yet
CVE-2026-20331
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20331
Cisco Secure Firewall Threat Defense (FTD) Software
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.0.2.1
7.0.3
7.0.4
7.0.5
No fixed version listed yet
CVE-2026-20333
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
9.16.1
9.16.1.28
9.16.2
9.16.2.3
9.16.2.7
9.16.2.11
9.16.2.13
9.16.2.14
No fixed version listed yet
CVE-2026-20333
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20333
Cisco Secure Firewall Threat Defense (FTD) Software
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.0.2.1
7.0.3
7.0.4
7.0.5
No fixed version listed yet
CVE-2026-20336
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
9.16.1
9.16.1.28
9.16.2
9.16.2.3
9.16.2.7
9.16.2.11
9.16.2.13
9.16.2.14
No fixed version listed yet
CVE-2026-20336
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20336
Cisco Secure Firewall Threat Defense (FTD) Software
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.0.2.1
7.0.3
7.0.4
7.0.5
No fixed version listed yet
CVE-2026-20334
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
9.16.1
9.16.1.28
9.16.2
9.16.2.3
9.16.2.7
9.16.2.11
9.16.2.13
9.16.2.14
No fixed version listed yet
CVE-2026-20334
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20334
Cisco Secure Firewall Threat Defense (FTD) Software
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.0.2.1
7.0.3
7.0.4
7.0.5
No fixed version listed yet
CVE-2026-20335
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
9.16.1
9.16.1.28
9.16.2
9.16.2.3
9.16.2.7
9.16.2.11
9.16.2.13
9.16.2.14
No fixed version listed yet
CVE-2026-20335
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-20335
Cisco Secure Firewall Threat Defense (FTD) Software
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.0.2.1
7.0.3
7.0.4
7.0.5
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.