Memory Exhaustion Vulnerability in Cisco Secure Firewall Adaptive Security Appliance
CVE-2026-20106

5.3MEDIUM

What is CVE-2026-20106?

A vulnerability in the Remote Access SSL VPN and HTTP management functionality of Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software can be exploited by an unauthenticated, remote attacker. By sending specially crafted packets to the Remote Access SSL VPN server, the attacker could exhaust device memory. This exploitation may result in a denial of service condition, necessitating a manual reboot to restore functionality. The root cause lies in the system's failure to appropriately validate user input, leaving it susceptible to potential attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.