Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-20335
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2026-20335 is an incorrect calculation vulnerability (CWE-682) affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software. It was internally discovered and publicly disclosed on September 16, 2026, as part of a broader Cisco software hardening release (advisory cisco-sa-hardening-asaftdfmc-uvpPROhN) that addresses eight CVEs across multiple CWE categories. Affected ASA versions span 9.16.x through 9.24.x, FTD versions span 7.0.x through 10.0.x, and FMC versions span 7.0.x through 10.0.x. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Cisco Advisory, GitHub Advisory).

Technical details

The vulnerability is rooted in incorrect calculation logic (CWE-682) within the ASA, FTD, and FMC software stacks, where flawed arithmetic or computational results are subsequently used in security-critical decisions or resource management operations. This class of flaw can manifest as integer overflows, off-by-one errors, or other miscalculations that corrupt control flow or memory state. The attack vector is network-based, requires no authentication and no user interaction, but does carry high attack complexity (AC:H), suggesting that exploitation requires specific conditions or precise timing to trigger the faulty calculation path. No public proof-of-concept or technical write-up detailing the exact exploitation mechanics has been released (Cisco Advisory, GitHub Advisory).

Impact

Successful exploitation of CVE-2026-20335 can result in high impact to confidentiality, integrity, and availability — potentially enabling an unauthenticated remote attacker to achieve arbitrary code execution, tamper with system integrity, or crash the affected firewall appliance. Because the affected products (ASA, FTD, FMC) are core network security infrastructure components, compromise could expose protected network segments, facilitate lateral movement into enterprise environments, and disrupt security enforcement across the perimeter. The scope is unchanged, meaning impact is confined to the vulnerable component itself, but the criticality of these devices amplifies the real-world risk (Cisco Advisory).

Exploitability

As of the disclosure date (September 16, 2026), Cisco PSIRT reports no public announcements or malicious use of CVE-2026-20335 specifically, and no proof-of-concept exploit is publicly available. The EPSS score is 0.0, reflecting very low current exploitation probability. Notably, the broader hardening advisory (cisco-sa-hardening-asaftdfmc-uvpPROhN) does note that two other CVEs in the same release (under CWE-284) are known to be actively exploited, but CVE-2026-20335 is not among them. CVE-2026-20335 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Cisco Advisory).

Mitigation and workarounds

Cisco has released fixed software versions and strongly recommends upgrading immediately. There are no workarounds available for CVE-2026-20335. Fixed releases are as follows:

Cisco Secure Firewall ASA Software:

  • 9.16 and earlier → 9.16.4.103
  • 9.18 → 9.18.4.94
  • 9.20 → 9.20.4.49
  • 9.22 → 9.22.3.26
  • 9.23 → 9.23.1.47
  • 9.24 → 9.24.1.26

Cisco Secure FTD and FMC Software:

  • 7.0 and earlier → 7.0.10
  • 7.2 → 7.2.12
  • 7.4 → 7.4.8
  • 7.6 → 7.6.6
  • 7.7 → 7.7.13
  • 10.0 → 10.0.2
  • 10.1 → 10.1.0

Organizations should prioritize patching given the critical role of these devices in network security, and consider network segmentation to limit exposure of affected appliances to untrusted networks while patching is underway (Cisco Advisory).

Community reactions

Cisco disclosed CVE-2026-20335 as part of a proactive internal security review, noting that the vulnerabilities were found using existing testing processes as well as frontier AI models — a notable disclosure about Cisco's use of AI-assisted security testing. The broader advisory received coverage from security aggregators including AusCERT, VulDB, and radar.offseq.com shortly after publication. No significant independent researcher commentary or social media discussion specific to CVE-2026-20335 has been identified, likely due to the absence of public exploitation and the bundled nature of the disclosure across eight CVEs (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20332CRITICAL9.9
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20336HIGH8.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20333HIGH8.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20334HIGH8.4
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20335HIGH8.1
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management