
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20014 is a Denial of Service (DoS) vulnerability in the IKEv2 feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. An authenticated, remote attacker with valid VPN user credentials can exploit improper IKEv2 packet processing to exhaust device memory, causing the affected device to reload and potentially disrupting services to dependent network devices. The vulnerability was disclosed on March 4, 2026, as part of Cisco's March 2026 Semiannual Cisco Secure Firewall Security Advisory Bundled Publication. It carries a CVSS v3.1 base score of 7.7 (High) (Cisco Advisory).
The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime) — the device fails to properly free memory during IKEv2 packet processing, leading to memory exhaustion (Cisco Advisory). Exploitation requires the attacker to be authenticated with valid VPN user credentials and to send specially crafted IKEv2 packets to an affected device over the network. The vulnerability only affects devices where the IKEv2 VPN feature is enabled, which can be confirmed via the CLI command show running-config crypto ikev2 | include enable. Affected ASA versions span 9.12.1 through 9.23.x, and affected FTD versions span 6.4.0 through 7.7.x (Cisco Advisory).
Successful exploitation causes memory exhaustion on the affected Cisco ASA or FTD device, forcing it to reload and resulting in a loss of availability for all network traffic and VPN services passing through the firewall. The CVSS scope is marked as "Changed," indicating that the impact extends beyond the vulnerable component itself — dependent network services and devices relying on the firewall for connectivity may also be disrupted. There is no confidentiality or integrity impact; the vulnerability is purely an availability concern (Cisco Advisory).
As of the advisory publication date, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild (Cisco Advisory). No public proof-of-concept exploit code has been identified (Feedly). The EPSS score is approximately 0.167%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid VPN credentials, which raises the bar compared to unauthenticated vulnerabilities in the same advisory bundle (CVE-2026-20013, CVE-2026-20015).
show memory CLI output; device reload events logged in show version or syslog with no corresponding maintenance window.show running-config crypto ikev2 | include enable confirming IKEv2 is active on one or more interfaces, indicating the device is in scope for this vulnerability (Cisco Advisory).Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability (Cisco Advisory). Administrators should upgrade to the following fixed releases: ASA Software — 9.16.4.85, 9.18.4.66, 9.20.4, 9.22.2.9, or 9.23.1.13; FTD Software — 7.0.9, 7.2.11, 7.4.3, 7.6.4, or 7.7.11. As interim risk reduction measures, restrict VPN access to trusted and authorized users only, implement network access controls to limit IKEv2 exposure to untrusted networks, and disable IKEv2 if it is not operationally required. Monitor devices for unexpected reloads that may indicate exploitation attempts.
The vulnerability was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG) and disclosed as part of Cisco's March 2026 semiannual firewall advisory bundle (Cisco Advisory). The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products that could allow for remote code execution and DoS, referencing this bundle (CIS Advisory). Community coverage was noted on security aggregation platforms including RedPacket Security and Hawk-Eye threat landscape digests, though no significant independent researcher commentary or social media discussion was identified beyond routine CVE tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."