Cisco has published a hardening release addressing CVE-2026-20329, a critical-severity (CVSS 9.9) set of improper exceptional-condition handling issues affecting Cisco Secure ASA, Firewall Threat Defense, and Firewall Management Center software.
What Is It
CVE-2026-20329 came out of an internal security review conducted by the engineering team behind Cisco Secure Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software. That review produced a software hardening release covering multiple internally discovered vulnerabilities. The issues grouped under this CVE identifier all concern improper handling of exceptional conditions, mapped to CWE-703 (the CWE pillar for that weakness class).
Why It Matters
NVD lists the flaw at CVSS 9.9, CRITICAL, with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Broken down, that means the vulnerability is reachable over the network, needs only low attack complexity, requires just low privileges, and needs no user interaction. The scope is changed, and the impact to confidentiality, integrity, and availability is High across the board. A 9.9 on a network security appliance is about as bad as the scoring model gets short of a clean 10.
No CISA KEV entry was supplied for this CVE, so there is no confirmed active exploitation and no KEV-mandated remediation deadline in the source material at this time.
What's Vulnerable
Cisco lists an extensive set of affected ASA Software releases spanning the 9.16, 9.18, 9.19, 9.20, 9.22, and 9.23 trains; including but not limited to 9.16.1 through 9.16.4.82, 9.18.1.3 through 9.18.4.57, 9.19.1.42, 9.20.1 through 9.20.3.16, 9.22.1.1 through 9.22.2, and 9.23.1. The advisory also covers Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software. Given the breadth of affected builds, operators should check their exact running version against Cisco's advisory rather than assuming a train is clear.
Patch Status
Cisco has shipped a software hardening release that addresses this and other internally discovered vulnerabilities. Consult the Cisco security advisory for fixed-version mapping. The record was published 2026-09-16 and remains in "Awaiting Analysis" status at NVD, so enrichment data such as CPE ranges is not yet finalized.
Sources
- Cisco Security Advisory; cisco-sa-hardening-asaftdfmc-uvpPROhN: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN
- NVD, CVE-2026-20329: https://nvd.nist.gov/vuln/detail/CVE-2026-20329