
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20335 is an incorrect calculation vulnerability (CWE-682) affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software. It was internally discovered and publicly disclosed on September 16, 2026, as part of a broader Cisco software hardening release (advisory cisco-sa-hardening-asaftdfmc-uvpPROhN) that addresses eight CVEs across multiple CWE categories. Affected ASA versions span 9.16.x through 9.24.x, FTD versions span 7.0.x through 10.0.x, and FMC versions span 7.0.x through 10.0.x. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Cisco Advisory, GitHub Advisory).
The vulnerability is rooted in incorrect calculation logic (CWE-682) within the ASA, FTD, and FMC software stacks, where flawed arithmetic or computational results are subsequently used in security-critical decisions or resource management operations. This class of flaw can manifest as integer overflows, off-by-one errors, or other miscalculations that corrupt control flow or memory state. The attack vector is network-based, requires no authentication and no user interaction, but does carry high attack complexity (AC:H), suggesting that exploitation requires specific conditions or precise timing to trigger the faulty calculation path. No public proof-of-concept or technical write-up detailing the exact exploitation mechanics has been released (Cisco Advisory, GitHub Advisory).
Successful exploitation of CVE-2026-20335 can result in high impact to confidentiality, integrity, and availability — potentially enabling an unauthenticated remote attacker to achieve arbitrary code execution, tamper with system integrity, or crash the affected firewall appliance. Because the affected products (ASA, FTD, FMC) are core network security infrastructure components, compromise could expose protected network segments, facilitate lateral movement into enterprise environments, and disrupt security enforcement across the perimeter. The scope is unchanged, meaning impact is confined to the vulnerable component itself, but the criticality of these devices amplifies the real-world risk (Cisco Advisory).
As of the disclosure date (September 16, 2026), Cisco PSIRT reports no public announcements or malicious use of CVE-2026-20335 specifically, and no proof-of-concept exploit is publicly available. The EPSS score is 0.0, reflecting very low current exploitation probability. Notably, the broader hardening advisory (cisco-sa-hardening-asaftdfmc-uvpPROhN) does note that two other CVEs in the same release (under CWE-284) are known to be actively exploited, but CVE-2026-20335 is not among them. CVE-2026-20335 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Cisco Advisory).
Cisco has released fixed software versions and strongly recommends upgrading immediately. There are no workarounds available for CVE-2026-20335. Fixed releases are as follows:
Cisco Secure Firewall ASA Software:
Cisco Secure FTD and FMC Software:
Organizations should prioritize patching given the critical role of these devices in network security, and consider network segmentation to limit exposure of affected appliances to untrusted networks while patching is underway (Cisco Advisory).
Cisco disclosed CVE-2026-20335 as part of a proactive internal security review, noting that the vulnerabilities were found using existing testing processes as well as frontier AI models — a notable disclosure about Cisco's use of AI-assisted security testing. The broader advisory received coverage from security aggregators including AusCERT, VulDB, and radar.offseq.com shortly after publication. No significant independent researcher commentary or social media discussion specific to CVE-2026-20335 has been identified, likely due to the absence of public exploitation and the bundled nature of the disclosure across eight CVEs (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."