Skip to content
VulniPulse
Advisory severityHigh8.6Cisco

High [CVE-2026-20154] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability

This high-severity Cisco advisory covers CVE-2026-20154 affecting Secure Firewall Adaptive Security Appliance (ASA) Software, Firepower 2100 Series, Firepower 1000 Series.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

cisco-sa-asa-ftd-logging-dos-ZXXNesfN Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
CiscoFirewallASA / FirepowerASA 5500
Open source advisory

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition.

An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation.

Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories.

In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

Affected products named by the advisory: Firepower 2100 Series; Firepower 1000 Series; ASA 5500-X Series Firewalls; 3000 Series Industrial Security Appliances (ISA); and 3 more.

Affected versions
  • Scope: This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco Secure Firewall ASA Software or Cisco Secure FTD Software and have syslog logging enabled for message 419002. Logging message 419002 is enabled by default when logging is enabled globally.
  • Release N/A (first fixed: 9.16 and earlier / 9.18)
  • Release 9.18.4.94 (first fixed: 9.18.4.135 / 9.20.4.235)
  • Release 9.22 (first fixed: 9.20.4.49 / 9.22.3.26)
  • Release 9.23.1.195 (first fixed: 9.23 / 9.23.1.47)
  • Release 9.24.1.155 (first fixed: 9.24 / 9.24.1.26)
  • Release 7.0 and earlier (first fixed: 7.0.10)
  • Release 7.2 (first fixed: 7.2.12)
  • Release 7.4 (first fixed: 7.4.8)
  • Release 7.6 (first fixed: 7.6.6)
  • Release 7.7 (first fixed: 7.7.13)
  • Release 10.0 (first fixed: 10.0.2)
  • Release 10.1 (first fixed: 10.1.0)

Official advisory · high-confidence parse· fetched 13 days ago·verify at source

Fixed versions
  • 9.16 and earlier / 9.18
  • 9.18.4.135 / 9.20.4.235
  • 9.20.4.49 / 9.22.3.26
  • 9.23 / 9.23.1.47
  • 9.24 / 9.24.1.26
  • 7.0.10
  • 7.2.12
  • 7.4.8
  • 7.6.6
  • 7.7.13
  • 10.0.2
  • 10.1.0

Official advisory · high-confidence parse· fetched 13 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
  • Release N/A: upgrade to 9.16 and earlier / 9.18.
  • Release 9.18.4.94: upgrade to 9.18.4.135 / 9.20.4.235.
  • Release 9.22: upgrade to 9.20.4.49 / 9.22.3.26.
  • Release 9.23.1.195: upgrade to 9.23 / 9.23.1.47.
  • Release 9.24.1.155: upgrade to 9.24 / 9.24.1.26.
  • Release 7.0 and earlier: upgrade to 7.0.10.
  • Release 7.2: upgrade to 7.2.12.
  • Release 7.4: upgrade to 7.4.8.
Temporary workarounds
  • There is a workaround that addresses this vulnerability. Rate limit in Cisco Secure Firewall ASA Software or Cisco Secure FTD Software using the methods described in the following sections.
  • Cisco Secure Firewall ASA Software
  • For devices that are running Cisco Secure Firewall ASA Software, append in global configuration mode and manually rate limit using the logging rate-limit 100 1 message 419002 command.
  • In the following example, message 419002 is limited to a rate of 100 messages per second, which will prevent successful exploitation of this vulnerability:
  • ASA(config)# logging rate-limit 100 1 message 419002
  • Cisco Secure FTD Software
  • For devices that are running Cisco Secure FTD Software, use one of the following options:
  • Choose Secure Firewall Management Center (FMC) > Devices > Platform Settings > Rate Limit > Syslog Level and deploy the appropriate policies. For more information, see Configure Logging on FTD via FMC.
  • Choose Firewall Device Manager (FTD) > Device > System Settings > Logging and rate limit message 419002 to 100 messages per second. For more information, see Configure and Verify Syslog in Firepower Device Manager.
  • While this workaround has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer depl…

Official advisory · high-confidence parse· fetched 13 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.