Cisco ASA / Firepower Vulnerabilities & Security Advisories
49 advisories tracked · Cisco Security Advisories · 7 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Cisco advisory that VulniPulse classified as ASA / Firepower, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 7 critical, 17 high, 24 medium.
Android app · Google Play
Monitor Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Cisco Security Advisories
Polled via the official Cisco PSIRT RSS feed. Advisory pages are fetched for new items to extract fixed software and workarounds.
Latest Cisco ASA / Firepower advisories
Medium [CVE-2026-20091] Cisco FXOS and UCS Manager Software Stored Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious data into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affecte… Affected products named by the advisory: Cisco Unified Computing System (Managed); Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 4 more.
Medium [CVE-2026-20099] Cisco FXOS and UCS Manager Software Command Injection Vulnerability
A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root. This vulnerability is due to insufficient input validation of command arguments supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlyi… Affected products named by the advisory: Cisco Unified Computing System (Managed); Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 4 more.
Medium [CVE-2026-20026 +1] Multiple Cisco Products Snort 3 Distributed Computing Environment/Remote Procedure Call Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the processing of Distributed Computing Environment Remote Procedure Call (DCE/RPC) requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, which would result in an interruption of packet inspection. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are workarounds that address these vulnerabilities. Affected products named by the advisory: Cisco UTD SNORT IPS Engine Software; Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.0.1.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.0.2.1; and 1 more.
Medium [CVE-2023-20269] vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user
An unauthenticated remote attacker could exploit a flaw in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user. The flaw is caused by improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. Establish a clientless SSL VPN session (only when running Cisco ASA Software Release 9.16 or earlier). Affected products named by the advisory: Secure Firewall Adaptive Security Appliance (ASA) Software; ASA 5500-X Series Firewalls; 3000 Series Industrial Security Appliances (ISA); Firepower 9000 Series; and 4 more. Affected products named by the advisory: Firepower 4100 Series; Adaptive Security Virtual Appliance (ASAv); Firepower 2100 Series; Firepower 1000 Series.