Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-20135

CVE-2026-20135: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

1 advisory
  • Advisory severityHigh

    High [CVE-2026-20135] Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability

    cisco-sa-ftd-tls1Source published

    A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the LINA process to crash, which would cause the device to reload. The reload can happen before or after authentication of the connection. Note: TLS 1.3 connections include both data traffic and user-management traffic. Cisco has released software updates…

    Affected products in this advisory
    • Cisco Secure Firewall Threat Defense (FTD) Software
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.
    Workarounds
    • There are no workarounds that address this vulnerability.
    • However, as a mitigation, administrators may temporarily remove TLS 1.3 from the configuration of the device.
    • Use Cisco Secure FMC Software and a FlexConfig object to set the minimum and maximum TLS version to TLS 1.2.
    • For more information about FlexConfig objects, see the FlexConfig Policies for FTD chapter of the Firepower Management Center Configuration Guide.

    3 more entries in the full advisory.

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery