
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20012 is a memory leak vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software. It allows an unauthenticated, remote attacker to trigger a denial of service (DoS) condition by sending crafted IKEv2 packets to an affected device. The vulnerability was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG) and first published on March 25, 2026, as part of the March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication. It carries a CVSS v3.1 base score of 8.6 (High) (Cisco Advisory).
The vulnerability is classified as CWE-401 (Missing Release of Memory after Effective Lifetime), caused by improper parsing of IKEv2 packets in the affected Cisco software. When a device with IKEv2 (including G-IKEv2) enabled receives specially crafted IKEv2 packets, it fails to properly release allocated memory, resulting in a memory leak. No authentication, user interaction, or special privileges are required to exploit this flaw — an attacker only needs network access to a device listening on UDP ports 500 or 4500 with IKEv2 enabled. Cisco Bug IDs CSCwq01495 and CSCwq01523 track this issue (Cisco Advisory).
On Cisco IOS and IOS XE Software, successful exploitation causes the affected device to reload, resulting in a complete denial of service. On Cisco Secure Firewall ASA and FTD Software, exploitation leads to partial memory exhaustion, causing system instability such as the inability to establish new IKEv2 VPN sessions; recovery requires a manual reboot of the device. There is no confidentiality or integrity impact — the vulnerability is limited to availability — but disruption of VPN infrastructure and network routing devices can have significant operational consequences for affected organizations (Cisco Advisory, Feedly).
show memory or equivalent diagnostic commands (Cisco Advisory).Cisco has released software updates that address this vulnerability; there are no workarounds available. Administrators should use the Cisco Software Checker to identify the earliest fixed release for their specific software version and platform. As an interim measure, organizations should consider implementing network-level access controls (e.g., ACLs or firewall rules) to restrict IKEv2 traffic (UDP ports 500 and 4500) to trusted peer IP addresses only, reducing the attack surface until patching is complete. Devices not using IKEv2 should have the feature disabled to eliminate exposure entirely (Cisco Advisory).
The vulnerability was covered in weekly threat landscape digests and security news aggregators shortly after disclosure, reflecting standard industry attention for a High-severity Cisco advisory. No notable independent researcher commentary or significant social media debate has been identified beyond routine CVE tracking and aggregation. The disclosure was part of Cisco's March 2026 Semiannual IOS and IOS XE Software Security Advisory Bundled Publication, which is a well-established coordinated disclosure process (Cisco Advisory, Hawk-Eye Digest).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."