Improper Access Control in Cisco Secure Adaptive Security and Firewall Software
CVE-2026-20332

9.9CRITICAL

What is CVE-2026-20332?

The recent review of Cisco's security offerings revealed critical improper access control issues in its Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software. These vulnerabilities, identified as part of a proactive security initiative, can potentially lead to unauthorized access and manipulation of security controls, thereby jeopardizing the integrity of the affected systems. Users are urged to apply the latest software hardening update to mitigate these risks and enhance their network security posture.

Affected Version(s)

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1.28

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.