Medium [CVE-2026-20102] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SAML Reflected Cross-Site Scripting Vulnerability
This medium-severity Cisco advisory covers CVE-2026-20102; related products: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1.28, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.3, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.7.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the SAML feature and access sensitive, browser-based information.
This vulnerability is due to insufficient input validation of multiple HTTP parameters. An attacker could exploit this vulnerability by persuading a user to access a malicious link.
A successful exploit could allow the attacker to conduct a reflected XSS attack through an …
Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1.28; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.7; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.11; and 3 more.
- Scope: At the time of publication, this vulnerability affected Cisco devices if they were running a vulnerable release of Cisco Secure Firewall ASA Software or Secure FTD Software and had Internet Key Exchange version 2 (IKEv2) or Remote Access SSL VPN functionality configured with SAML 2.0 SSO.
Official advisory · high-confidence parse· fetched 3 months ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 3 months ago·verify at source
Mitigation checklist
- There are no workarounds that address this vulnerability.
Official advisory · high-confidence parse· fetched 3 months ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.