Description
A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls.

This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Access Control Bypass
Action: Immediate Patch
AI Analysis

Impact

A logic error in the ACL Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software allows an unauthenticated, remote attacker to send traffic that should be blocked through the device. If successful, the attacker bypasses configured access controls and can reach devices in protected networks.

Affected Systems

The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. No specific version information is provided in the advisory, so the impact applies to all releases prior to the published fix.

Risk and Exploitability

The CVSS score is 5.3, indicating a medium severity vulnerability. The EPSS score is less than 1%, implying a very low likelihood of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. The attack vector appears to be remote, unauthenticated traffic directed through the firewall. The exploitation path requires the attacker to craft traffic that matches a blocked ACL rule but is processed by the faulty OGS logic to be allowed.

Generated by OpenCVE AI on September 18, 2026 at 00:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the vendor‑released patch or upgrade for Cisco Secure Firewall ASA and FTD that fixes the ACL OGS bug
  • If a patch cannot be applied immediately, remove or disable OGS from ACL object groups or replace ACLs with non‑OGS configurations as a temporary workaround
  • Verify that the ACLs correctly block traffic by performing testing and network scans after any changes

Generated by OpenCVE AI on September 18, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco cisco:adaptive Security Appliance Software
Cisco secure Firewall Threat Defense
Vendors & Products Cisco
Cisco cisco:adaptive Security Appliance Software
Cisco secure Firewall Threat Defense

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.
Title CIsco FTD Bypass Access List
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}


Subscriptions

Cisco Cisco:adaptive Security Appliance Software Secure Firewall Threat Defense
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T19:08:46.060Z

Reserved: 2025-10-08T11:59:15.377Z

Link: CVE-2026-20121

cve-icon Vulnrichment

Updated: 2026-09-17T15:56:42.947Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:07.467

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:38:04Z

Weaknesses