Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-20049

CVE-2026-20049: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

1 advisory
  • Advisory severityHigh7.7

    High [CVE-2026-20049] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability

    cisco-sa-asaftd-esp-dos-uv7yD8P5Source published Source updated

    A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the allocation of an insufficiently sized block of memory. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could al…

    Related products — impact not confirmed
    • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.7
    • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.10
    • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.13
    • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.8

    6 more entries in the full advisory.

    Source-reported affected versions
    • Scope: This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco Secure Firewall ASA Software or Secure FTD Software and are configured to use GCM encryption for IPsec IKEv2.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.
    Workarounds
    • There are no workarounds that address this vulnerability.

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery