
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20070 is a reflected cross-site scripting (XSS) vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. It allows an unauthenticated, remote attacker to execute arbitrary HTML or script code in a victim's browser within the context of the VPN web server. The vulnerability was first published on March 4, 2026, and was discovered internally during the resolution of a Cisco TAC support case. Affected products include Cisco ASA Software (versions from 9.12.x through 9.23.x) and Cisco FTD Software (versions from 6.4.0 through 7.7.x) when configured with IKEv2 Remote Access VPN with client services or SSL VPN. It carries a CVSS v3.1 base score of 6.1 (Medium) (Cisco Advisory).
The root cause is improper neutralization of script-related HTML tags in a web page (CWE-80), specifically due to insufficient validation of user-supplied input in HTTP requests processed by the VPN web services component. An attacker exploits this by crafting a malicious URL or web page that, when visited by a victim, submits malicious input to the affected ASA or FTD VPN web interface. The attack requires user interaction (the victim must follow a crafted link) and no authentication or privileges are needed on the part of the attacker. The vulnerability only affects devices with IKEv2 Remote Access VPN with client services enabled (crypto ikev2 enable client-services port) or SSL VPN enabled (webvpn enable); devices configured solely for IKEv2 without client services are not affected (Cisco Advisory).
Successful exploitation allows an attacker to execute arbitrary HTML or JavaScript in the victim's browser within the security context of the VPN web server, potentially enabling session hijacking, credential theft, phishing overlays, or redirection to malicious sites. The confidentiality and integrity impacts are rated Low (limited to browser-context data), and there is no direct availability impact. While the vulnerability does not grant direct access to the firewall's administrative functions, it could be chained with social engineering to harvest VPN credentials or session tokens from users accessing the affected device's web portal (Cisco Advisory).
<script>, javascript:, onerror=, or similar XSS payloads; repeated requests from the same source IP with varying encoded payloads.Cisco has released fixed software versions addressing this vulnerability; administrators should use the Cisco Software Checker to identify the appropriate fixed release for their specific ASA or FTD version. There are no workarounds available for this vulnerability. As an interim risk reduction measure, organizations can restrict access to the VPN web portal to trusted IP ranges and ensure that only necessary VPN features (IKEv2 with client services or SSL VPN) are enabled. Devices that do not use IKEv2 Remote Access VPN with client services or SSL VPN are not affected and require no action (Cisco Advisory).
The vulnerability was disclosed as part of Cisco's March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products. No significant independent researcher commentary or notable social media discussion has been identified for this specific CVE, consistent with its Medium severity rating and lack of known active exploitation (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."