Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20333 are related to incorrect comparison conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-697.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential Logic Bypass Leading to Unauthorized Access
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from incorrect comparison conditions, classified under CWE-697, which can enable an attacker to bypass intended controls. While the exact downstream impact is not specified in the advisory, such logic flaws typically allow an adversary to gain unintended privileges or access. The description indicates that the flaw was internally discovered and addressed in a hardening release, suggesting that the vulnerability could have allowed unauthorized actions if exploited.

Affected Systems

Affected systems include Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC). No specific version information was provided, so administrators should assume that all current supported releases may contain the flaw until a patched version is identified.

Risk and Exploitability

The CVSS score of 8.8 classifies this issue as high severity. The EPSS score of less than 1% indicates a low probability of exploitation. This vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been targeted by known exploitation campaigns. Nonetheless, the logic bypass presents a clear attack vector for adversaries who can target the firmware or management interfaces, potentially leading to unauthorized configuration changes or elevated privileges.

Generated by OpenCVE AI on September 18, 2026 at 01:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Cisco Secure Firewall Adaptive Security Appliance to the latest hardening release released by Cisco
  • Upgrade Cisco Secure Firewall Threat Defense to the latest hardening release released by Cisco
  • Upgrade Cisco Secure Firewall Management Center to the latest hardening release released by Cisco

Generated by OpenCVE AI on September 18, 2026 at 01:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20333 are related to incorrect comparison conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-697.
Title Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Incorrect Comparison Vulnerabilities
Weaknesses CWE-697
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T19:10:06.359Z

Reserved: 2025-10-08T11:59:15.412Z

Link: CVE-2026-20333

cve-icon Vulnrichment

Updated: 2026-09-17T11:31:41.774Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:10.690

Modified: 2026-09-18T20:17:14.523

Link: CVE-2026-20333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T01:45:16Z

Weaknesses