CVE-2026-20070
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2026-20070 is a reflected cross-site scripting (XSS) vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. It allows an unauthenticated, remote attacker to execute arbitrary HTML or script code in a victim's browser within the context of the VPN web server. The vulnerability was first published on March 4, 2026, and was discovered internally during the resolution of a Cisco TAC support case. Affected products include Cisco ASA Software (versions from 9.12.x through 9.23.x) and Cisco FTD Software (versions from 6.4.0 through 7.7.x) when configured with IKEv2 Remote Access VPN with client services or SSL VPN. It carries a CVSS v3.1 base score of 6.1 (Medium) (Cisco Advisory).

Technical details

The root cause is improper neutralization of script-related HTML tags in a web page (CWE-80), specifically due to insufficient validation of user-supplied input in HTTP requests processed by the VPN web services component. An attacker exploits this by crafting a malicious URL or web page that, when visited by a victim, submits malicious input to the affected ASA or FTD VPN web interface. The attack requires user interaction (the victim must follow a crafted link) and no authentication or privileges are needed on the part of the attacker. The vulnerability only affects devices with IKEv2 Remote Access VPN with client services enabled (crypto ikev2 enable client-services port) or SSL VPN enabled (webvpn enable); devices configured solely for IKEv2 without client services are not affected (Cisco Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary HTML or JavaScript in the victim's browser within the security context of the VPN web server, potentially enabling session hijacking, credential theft, phishing overlays, or redirection to malicious sites. The confidentiality and integrity impacts are rated Low (limited to browser-context data), and there is no direct availability impact. While the vulnerability does not grant direct access to the firewall's administrative functions, it could be chained with social engineering to harvest VPN credentials or session tokens from users accessing the affected device's web portal (Cisco Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Cisco ASA or FTD devices with SSL VPN or IKEv2 Remote Access VPN (with client services) enabled, using tools like Shodan or Censys to locate exposed VPN web portals.
  2. Craft malicious payload: Construct a URL or web page that submits a crafted HTTP request containing malicious HTML or JavaScript to the vulnerable VPN web services endpoint on the target device.
  3. Deliver the link: Use phishing, email, or social engineering to persuade a legitimate VPN user (e.g., an employee) to click the crafted link or visit the attacker-controlled page.
  4. XSS execution: When the victim's browser processes the response from the affected VPN web server, the injected script executes in the browser within the context of the VPN web server's origin.
  5. Achieve objective: The attacker can steal session cookies, capture credentials entered on the VPN portal, redirect the user to a phishing page, or perform other browser-based actions on behalf of the victim (Cisco Advisory).

Indicators of compromise

  • Network: Unusual or unexpected HTTP requests to the VPN web portal containing encoded script tags, JavaScript event handlers, or HTML injection strings in URL parameters or form fields; outbound connections from victim browsers to unknown external domains shortly after accessing the VPN portal.
  • Logs: ASA/FTD web server access logs showing requests to VPN web endpoints with suspicious query strings containing <script>, javascript:, onerror=, or similar XSS payloads; repeated requests from the same source IP with varying encoded payloads.
  • Browser/Client: Unexpected redirects or pop-ups when users access the VPN web portal; browser security warnings about mixed content or cross-origin requests originating from the VPN portal domain.

Mitigation and workarounds

Cisco has released fixed software versions addressing this vulnerability; administrators should use the Cisco Software Checker to identify the appropriate fixed release for their specific ASA or FTD version. There are no workarounds available for this vulnerability. As an interim risk reduction measure, organizations can restrict access to the VPN web portal to trusted IP ranges and ensure that only necessary VPN features (IKEv2 with client services or SSL VPN) are enabled. Devices that do not use IKEv2 Remote Access VPN with client services or SSL VPN are not affected and require no action (Cisco Advisory).

Community reactions

The vulnerability was disclosed as part of Cisco's March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products. No significant independent researcher commentary or notable social media discussion has been identified for this specific CVE, consistent with its Medium severity rating and lack of known active exploitation (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20012HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 25, 2026
CVE-2026-20025MEDIUM6.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20023MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20022MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20024MEDIUM5.7
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management