Cisco Security Advisories & CVEs
193 advisories tracked · Cisco Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Cisco device is affected
Pick your device's OS (and platform, where it matters), choose the software release it runs, and we'll check it against Cisco's recent security advisories — the same data behind the Cisco Software Checker.
Official source
Cisco Security Advisories
Polled via the official Cisco PSIRT RSS feed. Advisory pages are fetched for new items to extract fixed software and workarounds.
Latest Cisco advisories
Critical [CVE-2026-20131] Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC…
Critical [CVE-2026-20079] Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication.
High [CVE-2026-20049] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability
A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the allocation of an insufficiently sized block of memory. A successful exploit could al… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.7; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.10; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.13; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.8; and 5 more.
High [CVE-2026-20039] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to ineffective memory management of the VPN web server. An attacker could exploit this vulnerability by sending a large number of crafted HTTP requests to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Cisco has r… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.4; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 3 more.
High [CVE-2026-20082] Cisco Secure Firewall Adaptive Security Appliance Software TCP Flood Denial of Service Vulnerability
A vulnerability in the handling of the embryonic connection limits in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause incoming TCP SYN packets to be dropped incorrectly. This vulnerability is due to improper handling of new, incoming TCP connections that are destined to management or data interfaces when the device is under a TCP SYN flood attack. An attacker could exploit this vulnerability by sending a crafted stream of traffic to an affected device. A successful exploit could allow the attacker to prevent all incom… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20.4.14; FTD; FMC.
High [CVE-2026-20062] Cisco Secure Firewall Adaptive Security Appliance Software Multiple Context Mode SCP Unauthorized File Access Vulnerability
A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authenticated, local attacker with administrative privileges in one context to copy files to or from another context, including configuration files. This vulnerability is due to improper access controls for Secure Copy Protocol (SCP) operations when the Cisco SSH stack is enabled. An attacker could exploit this vulnerability by authenticating to a non-admin context of the device and issuing crafted SCP copy commands in that non-admin context. A successful ex… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.7; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.9; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.10; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.11; and 5 more.
High [CVE-2026-20001 +2] Cisco Secure Firewall Management Center Software SQL Injection Vulnerabilities
Multiple vulnerabilities in the web-based management interface and REST API of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory … Affected products named by the advisory: Cisco Secure Firewall Management Center (FMC) 6.4.0.1; Cisco Secure Firewall Management Center (FMC) 6.4.0.3; Cisco Secure Firewall Management Center (FMC) 6.4.0.2; Cisco Secure Firewall Management Center (FMC) 6.4.0.4; and 3 more.
High [CVE-2026-20013 +2] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities
Multiple vulnerabilities in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow a remote attacker to leak memory when parsing IKEv2 packets, triggering a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of the March 2026 release… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.4; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 3 more.
High [CVE-2026-20100 +4] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerabilities
Multiple vulnerabilities in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow a remote attacker to cause an affected device to stop responding or to reload unexpectedly, resulting in a denial of service (DoS) condition that may require a manual reboot. For more information about these vulnerabilities, see the Details section of this advisory. Affected products named by the advisory: Firepower 2100 Series; ASA 5500-X Series Firewalls; 3000 Series Industrial Security Appliances (ISA); Firepower 9000 Series; and 3 more. Affected products named by the advisory: Firepower 4100 Series; Adaptive Security Virtual Appliance (ASAv); Firepower 1000 Series.
Medium [CVE-2026-20005 +4] Multiple Cisco Products Snort 3 Denial of Service Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Adv… Affected products named by the advisory: Cisco Cyber Vision; Cisco UTD SNORT IPS Engine Software; Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.0.1.1; and 1 more.
Medium [CVE-2026-20009] Cisco Secure Firewall Adaptive Security Appliance Software SSH Partial Private Key Authentication Bypass Vulnerability
A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to log in to a Cisco Secure Firewall ASA device and execute commands as a specific user. This vulnerability is due to insufficient validation of user input during the SSH authentication phase. An attacker could exploit this vulnerability by submitting crafted input during SSH authentication to an affected device. A successful exploit could allow the attacker to log in to the de… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.7; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.9; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.10; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.11; and 5 more.
Medium [CVE-2026-20052] Cisco Secure Firewall Threat Defense Software Snort 3 SSL Memory Management Denial of Service Vulnerability
A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. This vulnerability is due to a logic error in memory management when a device is performing Snort 3 SSL packet inspection. An attacker could exploit this vulnerability by sending crafted SSL packets through an established connection to be parsed by the Snort 3 Detection Engine. A successful exploit could allow the attacker to cause a denial of service (DoS) c… Affected products named by the advisory: Cisco Secure Firewall Threat Defense (FTD) Software 7.4.0; Cisco Secure Firewall Threat Defense (FTD) Software 7.4.1.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.4.2.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.6.0; and 2 more.
Medium [CVE-2026-20050] Cisco Secure Firewall Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability
A vulnerability in the Do Not Decrypt exclusion feature of the SSL decryption feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management during the inspection of TLS 1.2 encrypted traffic. An attacker could exploit this vulnerability by sending crafted TLS 1.2 encrypted traffic through an affected device. A successful exploit could allow the attacker to cause a reload of an affected device. Note: This vulnerability on… Affected products named by the advisory: Cisco Secure Firewall Threat Defense (FTD) Software 7.1.0.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.1.0.2; Cisco Secure Firewall Threat Defense (FTD) Software 7.1.0.3; Cisco Secure Firewall Threat Defense (FTD) Software 7.2.0.1; and 4 more.
Medium [CVE-2026-20006] Cisco Secure Firewall Threat Defense Software TLS with Snort 3 Detection Engine Denial of Service Vulnerability
A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpectedly restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper implementation of the TLS protocol. An attacker could exploit this vulnerability by sending a crafted TLS packet to an affected system. A successful exploit could allow the attacker to cause a device that is running Cisco Secure FTD Software to drop network… Affected products named by the advisory: Cisco Secure Firewall Threat Defense (FTD) Software 7.2.0.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.2.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.2.2; Cisco Secure Firewall Threat Defense (FTD) Software 7.2.3; and 4 more.
Medium [CVE-2026-20020 +5] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software OSPF Protocol Vulnerabilities
Multiple vulnerabilities in the OSPF feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of the March 2026 release of the Cisco Secure Firewall… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.4; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 3 more.
Medium [CVE-2026-20007] Cisco Secure Firewall Threat Defense Software Snort Deep Inspection Bypass Vulnerability
A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Snort rules and allow traffic onto the network that should have been dropped. This vulnerability is due to a logic error in the integration of the Snort Engine rules with Cisco Secure FTD Software that could allow different Snort rules to be hit when deep inspection of the packet is performed for the inner and outer connections. An attacker could exploit this vulnerability by sending crafted traffic to a… Affected products named by the advisory: Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.0.1.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.0.2.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.0.3; and 3 more.
Medium [CVE-2026-20008] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability
A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root. This vulnerability exists because user-provided input is not properly sanitized. An attacker could exploit this vulnerability by crafting valid Lua code and submitting it as a malicious parameter for a CLI command. A successful exploit could allow the attacker to inject Lua code, wh… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.4; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 3 more.
Medium [CVE-2026-20102] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SAML Reflected Cross-Site Scripting Vulnerability
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the SAML feature and access sensitive, browser-based information. This vulnerability is due to insufficient input validation of multiple HTTP parameters. An attacker could exploit this vulnerability by persuading a user to access a malicious link. A successful exploit could allow the attacker to conduct a reflected XSS attack through an … Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1.28; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.7; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.11; and 3 more.
Medium [CVE-2026-20073] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Access Control List Bypass Vulnerability
A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should be denied through an affected device. This vulnerability is due to improper error handling when an affected device that is joining a cluster runs out of memory while replicating access control rules. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls an… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.4; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 3 more.
Medium [CVE-2026-20070] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Cross-Site Scripting Vulnerability
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by persuading a user to follow a link to a malicious website that is designed to submit malicious input to the affected application. A su… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.4; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 3 more.