Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-20334
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2026-20334 is a vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software stemming from improper adherence to coding standards (CWE-710). It was discovered internally by Cisco's engineering team and publicly disclosed on September 16, 2026, as part of a broader software hardening release addressing eight CVEs. Affected ASA versions span 9.16.x through 9.24.x; affected FTD and FMC versions span 7.0.x through 10.0.x. It carries a CVSS v3.1 base score of 8.4 (High) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is classified under CWE-710 (Improper Adherence to Coding Standards), a pillar-level weakness encompassing multiple lower-level coding defects that can lead to resultant vulnerabilities or amplify their severity. The attack vector is network-based with low attack complexity, but exploitation requires high privileges and user interaction, and the scope is changed — indicating that a successful exploit can affect components beyond the vulnerable one. Cisco grouped multiple internally discovered coding-standard violations under this single CVE identifier as part of a structured disclosure approach. No specific technical write-ups or public proof-of-concept code have been released (Cisco Advisory, GitHub Advisory).

Impact

Successful exploitation can result in high impact to confidentiality, integrity, and availability of affected systems, with a changed scope indicating potential for cross-component compromise. An authenticated attacker with high privileges could leverage these coding-standard deficiencies to compromise Cisco firewall and management infrastructure, potentially enabling unauthorized data access, configuration manipulation, or service disruption. Given that ASA, FTD, and FMC are core network security components, compromise could facilitate broader lateral movement within an enterprise network (Cisco Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and Cisco PSIRT has not reported malicious use of CVE-2026-20334 specifically. The broader advisory notes that two other CVEs in the same hardening release (under CWE-284) are known to be actively exploited, but CVE-2026-20334 itself is not among them. The EPSS score is 0.0, reflecting very low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Cisco Advisory, Feedly).

Mitigation and workarounds

Cisco has released fixed software versions and states there are no workarounds available. Customers should upgrade to the following minimum fixed releases:

  • Cisco Secure Firewall ASA Software: 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47, 9.24.1.26
  • Cisco Secure FTD Software / Secure FMC Software: 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2, 10.1.0

Cisco strongly recommends upgrading to a fixed release rather than relying on any interim mitigation. Customers without a service contract should contact Cisco TAC with their product serial number to obtain the fixed software (Cisco Advisory).

Community reactions

Cisco framed this disclosure as part of a proactive internal security review, noting that frontier AI models were used alongside existing testing processes to discover the vulnerabilities — a notable disclosure about AI-assisted security testing. The broader advisory bundle (eight CVEs) received attention due to two related CVEs under CWE-284 being actively exploited, which may draw additional scrutiny to the full hardening release including CVE-2026-20334. No significant independent researcher commentary or social media discussion specific to CVE-2026-20334 has been identified (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20332CRITICAL9.9
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20336HIGH8.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20333HIGH8.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20334HIGH8.4
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20335HIGH8.1
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management