High [CVE-2026-20250] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability
This high-severity Cisco advisory covers CVE-2026-20250 affecting Secure Firewall Adaptive Security Appliance (ASA) Software, Secure Firewall 3100 Series, Secure Firewall 4200 Series.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device.
A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories.
In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.
Affected products named by the advisory: Secure Firewall 4200 Series.
- Scope: This vulnerability affects Cisco Secure Firewall 3100 Series and 4200 Series devices if they are running a vulnerable release of Cisco Secure Firewall ASA or Secure FTD Software and have DTLS flow offload enabled. DTLS flow offload is enabled by default.
- Release N/A (first fixed: 9.20 and earlier / 9.22)
- Release 9.22.3.26 (first fixed: 9.22.3.191 / 9.23.1.195)
- Release 9.23.1.47 (first fixed: 9.23.1.211 / 9.24.1.155)
- Release 7.6 (first fixed: 7.6.6)
- Release 7.7 (first fixed: 7.7.13)
- Release 10.0 (first fixed: 10.0.2)
- Release 10.1 (first fixed: 10.1.0)
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
- 9.20 and earlier / 9.22
- 9.22.3.191 / 9.23.1.195
- 9.23.1.211 / 9.24.1.155
- 7.6.6
- 7.7.13
- 10.0.2
- 10.1.0
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
Mitigation checklist
- Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
- Release N/A: upgrade to 9.20 and earlier / 9.22.
- Release 9.22.3.26: upgrade to 9.22.3.191 / 9.23.1.195.
- Release 9.23.1.47: upgrade to 9.23.1.211 / 9.24.1.155.
- Release 7.6: upgrade to 7.6.6.
- Release 7.7: upgrade to 7.7.13.
- Release 10.0: upgrade to 10.0.2.
- Release 10.1: upgrade to 10.1.0.
- There is a workaround that addresses this vulnerability. Use the no flow-offload-dtls CLI command to disable DTLS flow offload.
- Note: For devices that are running Cisco FTD Software, the no flow-offload-dtls command can be pushed using FlexConfig.
- Disabling DTLS flow offload will cause DTLS-encrypted traffic to be processed in software rather than hardware, which may reduce throughput and increase CPU utilization on the affected device. This impact will be more significant in deployments with a high volume of DTLS sessions.
- While this workaround has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer depl…
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.