Memory Exhaustion Vulnerability in Cisco Secure Firewall Adaptive Security Appliance
CVE-2026-20106
What is CVE-2026-20106?
A vulnerability in the Remote Access SSL VPN and HTTP management functionality of Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software can be exploited by an unauthenticated, remote attacker. By sending specially crafted packets to the Remote Access SSL VPN server, the attacker could exhaust device memory. This exploitation may result in a denial of service condition, necessitating a manual reboot to restore functionality. The root cause lies in the system's failure to appropriately validate user input, leaving it susceptible to potential attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved