Cisco has disclosed CVE-2026-20330, a critical-severity (CVSS 9.9) set of improper neutralization vulnerabilities in Cisco Secure Firewall ASA, Threat Defense, and Management Center software, addressed in a software hardening release.
What Is It
CVE-2026-20330 tracks multiple vulnerabilities discovered internally by Cisco during a comprehensive security review of Cisco Secure Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software. The issues are classified as improper neutralization problems grouped under CWE-707 (Improper Neutralization), the CWE Pillar covering failures to correctly sanitize or neutralize input before it is passed to a downstream component.
The CVE was published on 2026-09-16 by Cisco PSIRT and currently carries a status of "Awaiting Analysis" at NVD.
Why It Matters
The assigned CVSS 3.1 base score is 9.9 (Critical), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. That breaks down to: network-reachable, low attack complexity, only low privileges required, no user interaction, and, critically, a changed scope with high impact to confidentiality, integrity, and availability. A scope change at this score means successful exploitation can affect resources beyond the initially vulnerable component.
These products sit at network perimeters and manage security policy, so the combination of remote reach, minimal privilege requirements, and full CIA impact makes this a high-priority patching item.
As of publication, CVE-2026-20330 does not appear in the CISA Known Exploited Vulnerabilities catalog, so active exploitation is not confirmed at this time.
What's Vulnerable
Per Cisco's data, affected products are:
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Secure Firewall Threat Defense (FTD) Software
- Cisco Secure Firewall Management Center (FMC) Software
The affected ASA version list is extensive and spans multiple release trains, including 9.16.x (9.16.1 through 9.16.4.82+), 9.18.x (9.18.1.3 through 9.18.4.57+), 9.19.x, 9.20.x (through 9.20.3.16+), 9.22.x (through 9.22.2), and 9.23.1. Default status for unlisted versions is "unknown." Administrators should consult the Cisco advisory for the authoritative, complete version matrix rather than relying on a partial list. No CPE match data has been published by NVD yet.
Patch Status
Cisco has published a software hardening release addressing these internally discovered vulnerabilities. Fixed-version details are in Cisco Security Advisory cisco-sa-hardening-asaftdfmc-uvpPROhN. Operators running any affected ASA, FTD, or FMC release should identify their fixed target version in that advisory and upgrade.
Sources
- Cisco Security Advisory; cisco-sa-hardening-asaftdfmc-uvpPROhN: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN
- NVD, CVE-2026-20330: https://nvd.nist.gov/vuln/detail/CVE-2026-20330
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog