CVE-2026-20073
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2026-20073 is an access control list (ACL) bypass vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. It allows an unauthenticated, remote attacker to send traffic through an affected device that should otherwise be denied. The vulnerability affects devices deployed in a cluster configuration across a wide range of ASA and FTD software versions (ASA 9.12.x through 9.23.x; FTD 6.4.x through 7.7.x). It was first published on March 4, 2026, and carries a CVSS v3.1 base score of 5.8 (Medium) (Cisco Advisory).

Technical details

The root cause is classified as CWE-284 (Improper Access Control). When a node joins a cluster, memory exhaustion can occur during the rule replication process if the replicated configuration includes access control lists (ACLs) with a large number of access control entries (ACEs). Due to improper error handling in this out-of-memory condition, the joining node may complete cluster membership with an incomplete ACL ruleset. This means traffic that should be blocked by the missing ACEs is instead permitted to pass through the device. Exploitation requires no authentication, no user interaction, and is network-accessible, but the device must be operating in a cluster configuration — a significant precondition that limits the attack surface (Cisco Advisory).

Impact

A successful exploit allows an unauthenticated remote attacker to bypass access controls enforced by the affected firewall device, enabling traffic that should be denied to reach devices in protected network segments. The primary impact is to network integrity (low) and scope is changed, as the attacker can affect resources beyond the vulnerable component itself — specifically, hosts in protected networks behind the firewall. There is no direct confidentiality or availability impact from the vulnerability itself, though bypassing firewall controls could facilitate further lateral movement or attacks against otherwise-protected internal systems (Cisco Advisory).

Exploitation steps

  1. Reconnaissance: Identify Cisco ASA or FTD devices deployed in a cluster configuration that are running vulnerable software versions. Tools such as Shodan or Censys can be used to locate internet-facing Cisco firewall management interfaces; cluster configuration can sometimes be inferred from banner information or network topology.
  2. Identify timing window: The vulnerability is only exploitable when a node is actively joining the cluster and memory exhaustion occurs during ACL replication — this is a transient condition that may occur during device restarts, failover events, or cluster scaling operations.
  3. Trigger or wait for the vulnerable state: An attacker with knowledge of the target environment may attempt to induce a cluster join event (e.g., by causing a node restart through other means) or simply monitor for periods when nodes are joining the cluster with large ACL configurations.
  4. Send blocked traffic: During the window when the joining node has an incomplete ACL (due to the memory exhaustion error), send traffic that would normally be denied by the missing ACEs. This traffic will be permitted to pass through the affected device and reach protected network segments.
  5. Access protected resources: Use the bypassed firewall to reach hosts or services in protected network zones that would otherwise be inaccessible (Cisco Advisory).

Indicators of compromise

  • Logs: Unexpected traffic flows logged in downstream systems (e.g., internal servers receiving connections from external IPs that should be blocked); absence of expected deny log entries in ASA/FTD syslog during cluster join events.
  • Device State: Output of show cluster info showing a node recently joined the cluster; review of show access-list output on a newly joined node revealing fewer ACEs than expected compared to the control node.
  • Network: Anomalous inbound connections to internal hosts from external sources that should be blocked by firewall policy, particularly during or shortly after cluster node join events.
  • Memory: System logs or SNMP traps indicating memory exhaustion events on ASA/FTD nodes during cluster join operations (Cisco Advisory).

Mitigation and workarounds

Cisco has released fixed software versions addressing this vulnerability; administrators should use the Cisco Software Checker tool to identify the appropriate fixed release for their deployment. There are no workarounds available for this vulnerability — upgrading to a fixed software release is the only remediation. Organizations should prioritize patching devices deployed in cluster configurations, as non-clustered deployments are not affected. To verify cluster status before patching, run show cluster info on the device CLI; if clustering is not configured, the device is not vulnerable (Cisco Advisory).

Community reactions

The vulnerability was disclosed as part of Cisco's March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products from this bundle. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-20073 has been identified, consistent with its medium severity rating and the absence of public exploit code (CIS Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20012HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 25, 2026
CVE-2026-20025MEDIUM6.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20023MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20022MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20024MEDIUM5.7
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management