Remote Access SSL VPN Vulnerability in Cisco Secure Firewall Products
CVE-2026-20103
What is CVE-2026-20103?
A vulnerability affecting the Remote Access SSL VPN functionality in Cisco's Secure Firewall ASA and FTD Software could enable an unauthenticated remote attacker to exploit device memory leading to a denial of service condition. This issue arises from insufficient validation of user inputs, allowing attackers to send specially crafted packets to the Remote Access SSL VPN server. Successful exploitation could result in the unavailability of VPN connections, causing interruptions while potentially leaving the management interface temporarily unresponsive.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.48
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.50
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.52
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved