Description
A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.

This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the LINA process to crash, which would cause the device to reload. The reload can happen before or after authentication of the connection.Note: TLS 1.3 connections include both data traffic and user-management traffic.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Update
AI Analysis

Impact

The vulnerability stems from improper buffer management in the TLS 1.3 implementation of Cisco Secure Firewall Threat Defense software. An unauthenticated attacker can send a crafted TLS 1.3 packet to a device’s listening socket, causing the LINA process to crash and forcing the device to reload. This results in an abrupt restart, exposing the system to a denial of service. The flaw is classified as CWE‑415, a flaw in memory handling that leads to process termination.

Affected Systems

Cisco Secure Firewall Threat Defense (FTD) Software is the only vendor and product identified as impacted. No specific version numbers were listed in the advisory, so all releases of the FTD product that include the TLS 1.3 implementation may be affected.

Risk and Exploitability

The CVSS score of 8.6 classifies the issue as high severity. The EPSS score indicates a very low probability of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. Nevertheless, the attack vector can be remote and does not require authentication, making it actionable by external actors. If exploited, the device will unpredictably reload, disrupting network security services. The likely path involves an attacker sending a malicious TLS 1.3 packet before or after authentication, triggering the buffer overflow and crash.

Generated by OpenCVE AI on September 17, 2026 at 22:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check Cisco’s official website or security advisory portal for an update that addresses the TLS 1.3 buffer handling flaw and apply the patch or firmware upgrade when available.
  • If an update is not yet released, configure the firewall to disable TLS 1.3 on its listening sockets to prevent the attacker from establishing connections that trigger the crash.
  • Continuously monitor device logs for unexpected reloads or LINA crashes and ensure that recovery processes are operational so the firewall can return to service quickly.

Generated by OpenCVE AI on September 17, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Threat Defense
Vendors & Products Cisco
Cisco secure Firewall Threat Defense

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the LINA process to crash, which would cause the device to reload. The reload can happen before or after authentication of the connection.Note:&nbsp;TLS 1.3 connections include both data traffic and user-management traffic.
Title Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability
Weaknesses CWE-415
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Cisco Secure Firewall Threat Defense
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T13:40:57.832Z

Reserved: 2025-10-08T11:59:15.381Z

Link: CVE-2026-20135

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:15.500Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:07.587

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:11:49Z

Weaknesses