Cisco disclosed CVE-2026-20332, a critical (CVSS 9.9) set of improper access control flaws in Secure ASA, Secure Firewall Threat Defense, and Secure Firewall Management Center software, found during an internal security review.
What Is It
CVE-2026-20332 tracks multiple vulnerabilities uncovered by Cisco's own engineering team during a comprehensive internal security review of Cisco Secure Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense Software, and Cisco Secure Firewall Management Center Software. The issues are improper access control problems grouped under CWE-284 (Improper Access Control, a CWE Pillar). Cisco addressed them collectively in a software hardening release rather than as individually detailed advisories.
Why It Matters
The CVSS v3.1 base score is 9.9, CRITICAL, with vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. That combination is about as bad as it gets short of no-auth exploitation: the flaws are reachable over the network, require low attack complexity, need only low privileges, and need no user interaction. The scope change (S:C) means a successful attack can affect resources beyond the vulnerable component, and impact is high across confidentiality, integrity, and availability.
The affected products are perimeter security devices and the management plane that governs them. Access control failures on a firewall or its management center undermine the control that the rest of the environment depends on.
CVE-2026-20332 does not appear in CISA's Known Exploited Vulnerabilities catalog as of publication, so active exploitation is not confirmed and no KEV-mandated remediation deadline applies.
What's Vulnerable
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, along with Secure Firewall Threat Defense and Secure Firewall Management Center Software. The affected version list is extensive, spanning the 9.16, 9.18, 9.19, 9.20, 9.22, and 9.23 ASA trains and many maintenance releases within each. Operators should treat any unpatched release in those trains as suspect and check their exact build against Cisco's advisory.
Patch Status
Cisco has published a software hardening release addressing the vulnerabilities. Consult the Cisco security advisory for the fixed version corresponding to your current train and upgrade accordingly. Cisco's advisory (cisco-sa-hardening-asaftdfmc-uvpPROhN) does not describe a workaround.
Sources
- NVD, CVE-2026-20332: https://nvd.nist.gov/vuln/detail/CVE-2026-20332
- Cisco Security Advisory (cisco-sa-hardening-asaftdfmc-uvpPROhN): https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog