Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.  

The vulnerabilities tracked by CVE-2026-20329 are related to issues concerning improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.
Published: 2026-09-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service or Service Instability due to improper exception handling
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper handling of exceptional conditions in the Cisco Secure Firewall components. According to the description, the software hardening release addresses multiple internally discovered weaknesses related to the Common Weakness Enumeration pillar CWE-703. The flaw can cause the system to behave unpredictably when unexpected events occur, potentially leading to a denial of service or service instability.

Affected Systems

The affected systems include Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Management Center (FMC), and Cisco Secure Firewall Threat Defense (FTD) Software. No specific version ranges are listed; any instance of these products running prior to the hardening release is potentially impacted.

Risk and Exploitability

The CVSS score of 9.9 indicates a critical severity. The EPSS score is less than 1%, indicating a low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Nevertheless, the high severity requires prompt action. While the description does not specify an exact exploit path, the vulnerability likely requires the ability to trigger exceptional conditions through management interfaces or normal operational states, making privileged access or remote management a probable attack vector.

Generated by OpenCVE AI on September 17, 2026 at 20:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and install the Cisco Secure Hardening Release for ASA, FTD, and FMC.
  • Reboot each device to enforce the new exception handling changes.
  • Reconfigure exception handling to the hardened defaults as documented in the release notes.

Generated by OpenCVE AI on September 17, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco adaptive Security Appliance Software
Cisco secure Firewall Management Center
Cisco secure Firewall Threat Defense
Vendors & Products Cisco
Cisco adaptive Security Appliance Software
Cisco secure Firewall Management Center
Cisco secure Firewall Threat Defense

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-20329 are related to issues concerning improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.
Title Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities
Weaknesses CWE-703
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Adaptive Security Appliance Software Secure Firewall Management Center Secure Firewall Threat Defense
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T19:09:48.774Z

Reserved: 2025-10-08T11:59:15.412Z

Link: CVE-2026-20329

cve-icon Vulnrichment

Updated: 2026-09-17T14:59:15.399Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:23.600

Modified: 2026-09-18T20:17:13.133

Link: CVE-2026-20329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:50Z

Weaknesses
  • CWE-703

    Improper Check or Handling of Exceptional Conditions