
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20073 is an access control list (ACL) bypass vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. It allows an unauthenticated, remote attacker to send traffic through an affected device that should otherwise be denied. The vulnerability affects devices deployed in a cluster configuration across a wide range of ASA and FTD software versions (ASA 9.12.x through 9.23.x; FTD 6.4.x through 7.7.x). It was first published on March 4, 2026, and carries a CVSS v3.1 base score of 5.8 (Medium) (Cisco Advisory).
The root cause is classified as CWE-284 (Improper Access Control). When a node joins a cluster, memory exhaustion can occur during the rule replication process if the replicated configuration includes access control lists (ACLs) with a large number of access control entries (ACEs). Due to improper error handling in this out-of-memory condition, the joining node may complete cluster membership with an incomplete ACL ruleset. This means traffic that should be blocked by the missing ACEs is instead permitted to pass through the device. Exploitation requires no authentication, no user interaction, and is network-accessible, but the device must be operating in a cluster configuration — a significant precondition that limits the attack surface (Cisco Advisory).
A successful exploit allows an unauthenticated remote attacker to bypass access controls enforced by the affected firewall device, enabling traffic that should be denied to reach devices in protected network segments. The primary impact is to network integrity (low) and scope is changed, as the attacker can affect resources beyond the vulnerable component itself — specifically, hosts in protected networks behind the firewall. There is no direct confidentiality or availability impact from the vulnerability itself, though bypassing firewall controls could facilitate further lateral movement or attacks against otherwise-protected internal systems (Cisco Advisory).
show cluster info showing a node recently joined the cluster; review of show access-list output on a newly joined node revealing fewer ACEs than expected compared to the control node.Cisco has released fixed software versions addressing this vulnerability; administrators should use the Cisco Software Checker tool to identify the appropriate fixed release for their deployment. There are no workarounds available for this vulnerability — upgrading to a fixed software release is the only remediation. Organizations should prioritize patching devices deployed in cluster configurations, as non-clustered deployments are not affected. To verify cluster status before patching, run show cluster info on the device CLI; if clustering is not configured, the device is not vulnerable (Cisco Advisory).
The vulnerability was disclosed as part of Cisco's March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products from this bundle. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-20073 has been identified, consistent with its medium severity rating and the absence of public exploit code (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."