Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-20336
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2026-20336 is a vulnerability class grouped under CWE-664 (Improper Control of a Resource Through its Lifetime), affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software. It was discovered internally by Cisco's engineering team and publicly disclosed on September 16, 2026, as part of a broader software hardening release addressing eight CVEs. Affected ASA versions span 9.16.x through 9.24.x, FTD versions span 7.0.x through 10.0.x, and FMC versions span 7.0.x through 10.0.x. The CVE carries a CVSS v3.1 base score of 8.8 (High) for the specific CWE-664 grouping, though the broader advisory carries a maximum score of 9.9 (Critical) across all grouped CVEs (Cisco Advisory, GitHub Advisory).

Technical details

The vulnerability is classified under CWE-664 (Improper Control of a Resource Through its Lifetime), which encompasses issues such as uninitialized variables, null pointer dereferences, and resource lifecycle mismanagement. Cisco's advisory describes this grouping as covering "uninitialized variables, null pointers, and resource lifecycle issues" within the ASA, FTD, and FMC software stacks. The attack vector is adjacent network (AV:A), requiring no authentication (PR:N) and no user interaction (UI:N), meaning an attacker positioned on the same network segment as the affected device can trigger the vulnerability without credentials. No public technical write-ups or proof-of-concept code have been identified at this time (Cisco Advisory, GitHub Advisory).

Impact

Successful exploitation can result in high impacts to confidentiality, integrity, and availability — an unauthenticated adjacent-network attacker may be able to read sensitive data from memory, modify system data, and crash the affected service. The affected products are core network security infrastructure (firewalls and their management platform), so compromise could expose network traffic, security policies, and credentials managed by these devices, and could facilitate lateral movement within the protected network. The scope is unchanged, meaning impact is contained to the vulnerable component itself, but given the role of these devices as network gatekeepers, the downstream risk to protected environments is significant (Cisco Advisory, Feedly).

Exploitability

There is no evidence of public proof-of-concept code or active in-the-wild exploitation of CVE-2026-20336 specifically. The EPSS score is 0.0, reflecting low current exploitation probability. Cisco PSIRT noted that while two other CVEs in the same hardening advisory (CVE-2026-20332, related to CWE-284) are known to be actively exploited, CVE-2026-20336 is not among them. The vulnerability is not listed in the CISA KEV catalog. The vulnerabilities in this advisory were discovered through internal security testing, including the use of frontier AI models (Cisco Advisory).

Mitigation and workarounds

Cisco has released fixed software versions to address CVE-2026-20336 and the other vulnerabilities in this hardening release. There are no workarounds available. Recommended fixed releases are:

  • Cisco Secure Firewall ASA Software: 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47, 9.24.1.26
  • Cisco Secure FTD Software / Secure FMC Software: 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2, 10.1.0

Organizations should upgrade to the appropriate fixed release as soon as possible. As an interim measure, restricting adjacent network access to affected devices from untrusted segments can reduce exposure (Cisco Advisory).

Community reactions

Cisco's PSIRT published the advisory on September 16, 2026, as part of a coordinated hardening release covering eight CVEs across ASA, FTD, and FMC software. Cisco noted that the vulnerabilities were discovered through internal security testing augmented by frontier AI models, highlighting an evolving approach to proactive vulnerability discovery. The broader advisory received coverage from AUSCERT (bulletins ESB-2026.11180 and ESB-2026.11208) and was indexed by VulDB and other aggregators shortly after publication. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-20336 has been identified (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20332CRITICAL9.9
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20336HIGH8.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20333HIGH8.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20334HIGH8.4
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesSep 16, 2026
CVE-2026-20335HIGH8.1
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management