CVE-2026-20154
CVE-2026-20154: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Cisco
1 advisory- Advisory severityHigh8.6
High [CVE-2026-20154] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability
cisco-sa-asa-ftd-logging-dos-ZXXNesfNSource published Source updated
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. This advisory is part of a group of advisories. For a complete list of the…
- Affected products in this advisory
- Secure Firewall Adaptive Security Appliance (ASA) Software
- Firepower 2100 Series
- Firepower 1000 Series
- ASA 5500-X Series Firewalls
4 more entries in the full advisory.
- Source-reported affected versions
- Scope: This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco Secure Firewall ASA Software or Cisco Secure FTD Software and have syslog logging enabled for message 419002. Logging message 419002 is enabled by default when logging is enabled globally.
- Release N/A (first fixed: 9.16 and earlier / 9.18)
- Release 9.18.4.94 (first fixed: 9.18.4.135 / 9.20.4.235)
- Release 9.22 (first fixed: 9.20.4.49 / 9.22.3.26)
9 more entries in the full advisory.
- Source-reported fixed versions
- 9.16 and earlier / 9.18
- 9.18.4.135 / 9.20.4.235
- 9.20.4.49 / 9.22.3.26
- 9.23 / 9.23.1.47
8 more entries in the full advisory.
- Mitigation guidance
- Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
- Release N/A: upgrade to 9.16 and earlier / 9.18.
- Release 9.18.4.94: upgrade to 9.18.4.135 / 9.20.4.235.
- Release 9.22: upgrade to 9.20.4.49 / 9.22.3.26.
5 more entries in the full advisory.
- Workarounds
- There is a workaround that addresses this vulnerability. Rate limit in Cisco Secure Firewall ASA Software or Cisco Secure FTD Software using the methods described in the following sections.
- Cisco Secure Firewall ASA Software
- For devices that are running Cisco Secure Firewall ASA Software, append in global configuration mode and manually rate limit using the logging rate-limit 100 1 message 419002 command.
- In the following example, message 419002 is limited to a rate of 100 messages per second, which will prevent successful exploitation of this vulnerability:
6 more entries in the full advisory.
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.