CVE-2026-20014
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2026-20014 is a Denial of Service (DoS) vulnerability in the IKEv2 feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. An authenticated, remote attacker with valid VPN user credentials can exploit improper IKEv2 packet processing to exhaust device memory, causing the affected device to reload and potentially disrupting services to dependent network devices. The vulnerability was disclosed on March 4, 2026, as part of Cisco's March 2026 Semiannual Cisco Secure Firewall Security Advisory Bundled Publication. It carries a CVSS v3.1 base score of 7.7 (High) (Cisco Advisory).

Technical details

The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime) — the device fails to properly free memory during IKEv2 packet processing, leading to memory exhaustion (Cisco Advisory). Exploitation requires the attacker to be authenticated with valid VPN user credentials and to send specially crafted IKEv2 packets to an affected device over the network. The vulnerability only affects devices where the IKEv2 VPN feature is enabled, which can be confirmed via the CLI command show running-config crypto ikev2 | include enable. Affected ASA versions span 9.12.1 through 9.23.x, and affected FTD versions span 6.4.0 through 7.7.x (Cisco Advisory).

Impact

Successful exploitation causes memory exhaustion on the affected Cisco ASA or FTD device, forcing it to reload and resulting in a loss of availability for all network traffic and VPN services passing through the firewall. The CVSS scope is marked as "Changed," indicating that the impact extends beyond the vulnerable component itself — dependent network services and devices relying on the firewall for connectivity may also be disrupted. There is no confidentiality or integrity impact; the vulnerability is purely an availability concern (Cisco Advisory).

Exploitability

As of the advisory publication date, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild (Cisco Advisory). No public proof-of-concept exploit code has been identified (Feedly). The EPSS score is approximately 0.167%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid VPN credentials, which raises the bar compared to unauthenticated vulnerabilities in the same advisory bundle (CVE-2026-20013, CVE-2026-20015).

Exploitation steps

  1. Reconnaissance: Identify Cisco ASA or FTD devices with IKEv2 VPN enabled by scanning for UDP port 500 (IKE) and UDP port 4500 (NAT-T) using tools such as Nmap or Shodan.
  2. Obtain VPN credentials: Acquire valid VPN user credentials through phishing, credential stuffing, or other means — authentication is required to exploit this vulnerability.
  3. Establish IKEv2 session: Initiate a legitimate IKEv2 VPN authentication exchange with the target device using the obtained credentials.
  4. Send crafted IKEv2 packets: Transmit specially crafted, authenticated IKEv2 packets designed to trigger the improper memory handling flaw in the device's IKEv2 processing code.
  5. Trigger memory exhaustion: Repeatedly send malformed packets to progressively exhaust available device memory, eventually causing the firewall to reload and resulting in a DoS condition (Cisco Advisory).

Indicators of compromise

  • Network: Unusual volume of authenticated IKEv2 traffic (UDP/500 or UDP/4500) from a single source IP; repeated IKEv2 session establishment attempts followed by abnormal packet sequences.
  • Logs: Cisco ASA/FTD system logs showing unexpected device reloads or crash events; memory allocation failure messages in system logs; IKEv2 processing errors or exceptions in the firewall event log.
  • Process/System: Rapid or progressive decline in available device memory observable via show memory CLI output; device reload events logged in show version or syslog with no corresponding maintenance window.
  • Configuration: Output of show running-config crypto ikev2 | include enable confirming IKEv2 is active on one or more interfaces, indicating the device is in scope for this vulnerability (Cisco Advisory).

Mitigation and workarounds

Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability (Cisco Advisory). Administrators should upgrade to the following fixed releases: ASA Software — 9.16.4.85, 9.18.4.66, 9.20.4, 9.22.2.9, or 9.23.1.13; FTD Software — 7.0.9, 7.2.11, 7.4.3, 7.6.4, or 7.7.11. As interim risk reduction measures, restrict VPN access to trusted and authorized users only, implement network access controls to limit IKEv2 exposure to untrusted networks, and disable IKEv2 if it is not operationally required. Monitor devices for unexpected reloads that may indicate exploitation attempts.

Community reactions

The vulnerability was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG) and disclosed as part of Cisco's March 2026 semiannual firewall advisory bundle (Cisco Advisory). The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products that could allow for remote code execution and DoS, referencing this bundle (CIS Advisory). Community coverage was noted on security aggregation platforms including RedPacket Security and Hawk-Eye threat landscape digests, though no significant independent researcher commentary or social media discussion was identified beyond routine CVE tracking.

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20349HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
YesYesAug 11, 2026
CVE-2026-20012HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesMar 25, 2026
CVE-2026-20025MEDIUM6.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20023MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20024MEDIUM5.7
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management