
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20336 is a vulnerability class grouped under CWE-664 (Improper Control of a Resource Through its Lifetime), affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software. It was discovered internally by Cisco's engineering team and publicly disclosed on September 16, 2026, as part of a broader software hardening release addressing eight CVEs. Affected ASA versions span 9.16.x through 9.24.x, FTD versions span 7.0.x through 10.0.x, and FMC versions span 7.0.x through 10.0.x. The CVE carries a CVSS v3.1 base score of 8.8 (High) for the specific CWE-664 grouping, though the broader advisory carries a maximum score of 9.9 (Critical) across all grouped CVEs (Cisco Advisory, GitHub Advisory).
The vulnerability is classified under CWE-664 (Improper Control of a Resource Through its Lifetime), which encompasses issues such as uninitialized variables, null pointer dereferences, and resource lifecycle mismanagement. Cisco's advisory describes this grouping as covering "uninitialized variables, null pointers, and resource lifecycle issues" within the ASA, FTD, and FMC software stacks. The attack vector is adjacent network (AV:A), requiring no authentication (PR:N) and no user interaction (UI:N), meaning an attacker positioned on the same network segment as the affected device can trigger the vulnerability without credentials. No public technical write-ups or proof-of-concept code have been identified at this time (Cisco Advisory, GitHub Advisory).
Successful exploitation can result in high impacts to confidentiality, integrity, and availability — an unauthenticated adjacent-network attacker may be able to read sensitive data from memory, modify system data, and crash the affected service. The affected products are core network security infrastructure (firewalls and their management platform), so compromise could expose network traffic, security policies, and credentials managed by these devices, and could facilitate lateral movement within the protected network. The scope is unchanged, meaning impact is contained to the vulnerable component itself, but given the role of these devices as network gatekeepers, the downstream risk to protected environments is significant (Cisco Advisory, Feedly).
There is no evidence of public proof-of-concept code or active in-the-wild exploitation of CVE-2026-20336 specifically. The EPSS score is 0.0, reflecting low current exploitation probability. Cisco PSIRT noted that while two other CVEs in the same hardening advisory (CVE-2026-20332, related to CWE-284) are known to be actively exploited, CVE-2026-20336 is not among them. The vulnerability is not listed in the CISA KEV catalog. The vulnerabilities in this advisory were discovered through internal security testing, including the use of frontier AI models (Cisco Advisory).
Cisco has released fixed software versions to address CVE-2026-20336 and the other vulnerabilities in this hardening release. There are no workarounds available. Recommended fixed releases are:
Organizations should upgrade to the appropriate fixed release as soon as possible. As an interim measure, restricting adjacent network access to affected devices from untrusted segments can reduce exposure (Cisco Advisory).
Cisco's PSIRT published the advisory on September 16, 2026, as part of a coordinated hardening release covering eight CVEs across ASA, FTD, and FMC software. Cisco noted that the vulnerabilities were discovered through internal security testing augmented by frontier AI models, highlighting an evolving approach to proactive vulnerability discovery. The broader advisory received coverage from AUSCERT (bulletins ESB-2026.11180 and ESB-2026.11208) and was indexed by VulDB and other aggregators shortly after publication. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-20336 has been identified (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."