Improper Control of Resource Lifetime in Cisco Secure Firewall Products
CVE-2026-20336

8.8HIGH

What is CVE-2026-20336?

Cisco has released a software hardening update for its Secure Adaptive Security Appliance, Firewall Threat Defense, and Management Center Software after identifying vulnerabilities associated with inadequate control of resource lifetimes. This proactive measure aims to enhance the security posture of these products against potential exploitations. The identified weaknesses fall under the Common Weakness Enumeration category CWE-664 and necessitate the attention of users to ensure proper security measures are in place.

Affected Version(s)

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1.28

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.