Description
A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls.

This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.
Published: 2026-09-16
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Access control bypass
Action: Patch Now
AI Analysis

Impact

The vulnerability is a logic flaw in the ACL Object Group Search implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD). It results in improper access control (CWE‑284) whereby an attacker can send traffic that should be blocked, enabling them to bypass configured ACLs and reach devices in protected networks. The primary impact is the ability to bypass organizational access controls, potentially exposing or sensitive internal resources.

Affected Systems

The affected systems are Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. No specific versions are listed in the advisory, so all deployments using these products could be vulnerable until the patch is applied.

Risk and Exploitability

The CVSS score of 5.8 indicates a moderate severity, and the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The vulnerability is not cataloged in the CISA KEV list. The exploit requires an unauthenticated remote attacker to craft traffic that is intended to be denied by the ACL but is instead allowed due to the logic error in populating group access control policies with Object Group Search. If exploited, the attacker would have compromised network perimeter defenses and could potentially gain lateral movement into the protected network.

Generated by OpenCVE AI on September 18, 2026 at 00:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco Secure Firewall firmware update that fixes the ACL Object Group Search logic error as per the Cisco advisory.
  • As an interim measure, disable or remove the ACL object groups that use Object Group Search until the patch is applied, or block the corresponding traffic via a separate rule.
  • Continuously monitor firewall logs and network traffic for evidence of bypassed ACLs and investigate any suspicious activity.

Generated by OpenCVE AI on September 18, 2026 at 00:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco adaptive Security Appliance Software
Cisco secure Firewall Threat Defense
Vendors & Products Cisco
Cisco adaptive Security Appliance Software
Cisco secure Firewall Threat Defense

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.
Title Cisco FTD ACL bypass vulnerability
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

Cisco Adaptive Security Appliance Software Secure Firewall Threat Defense
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T19:08:46.057Z

Reserved: 2025-10-08T11:59:15.377Z

Link: CVE-2026-20120

cve-icon Vulnrichment

Updated: 2026-09-17T16:03:46.919Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:07.343

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:51:03Z

Weaknesses