Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.  

The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
Published: 2026-09-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation with potential for remote code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper access control flaw that can allow an attacker to gain elevated privileges on Cisco Secure Firewall devices. With the flaw, a privileged operation could be executed beyond the authorized boundary, potentially enabling local or remote code execution and unauthorized configuration changes. The weakness is classified as CWE‑284, indicating that valid users can perform actions intended only for higher‑privileged accounts.

Affected Systems

The affected products are Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software. No specific version ranges are listed in the advisory, so all versions that have not received the hardening release may be vulnerable.

Risk and Exploitability

The CVSS score of 9.9 shows a high severity and the potential for complete system compromise. The EPSS score of <1% indicates that the exploitation probability is low at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the nature of the flaw and the description, the likely attack vector is remote network, where an attacker could send crafted traffic to privileged interfaces or exploit administrative endpoints to bypass access controls. The fixed hardening release mitigates the flaw and should be applied promptly to avoid exploitation.

Generated by OpenCVE AI on September 18, 2026 at 00:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Cisco’s hardening release to all ASA, FTD, and FMC devices to seal the access‑control gaps
  • Upgrade to the latest Software versions per the Cisco advisory to ensure the fix is in place
  • Restrict administrative and privileged access to trusted networks and enable multi‑factor authentication for all privileged users

Generated by OpenCVE AI on September 18, 2026 at 00:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco adaptive Security Appliance Software
Cisco secure Firewall Management Center
Cisco secure Firewall Threat Defense
Vendors & Products Cisco
Cisco adaptive Security Appliance Software
Cisco secure Firewall Management Center
Cisco secure Firewall Threat Defense

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
Title Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Adaptive Security Appliance Software Secure Firewall Management Center Secure Firewall Threat Defense
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T19:10:06.697Z

Reserved: 2025-10-08T11:59:15.412Z

Link: CVE-2026-20332

cve-icon Vulnrichment

Updated: 2026-09-17T11:31:51.169Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:10.480

Modified: 2026-09-18T20:17:14.310

Link: CVE-2026-20332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:31:13Z

Weaknesses