Impact
The vulnerability described in CVE‑2026‑20336 centers on CWE‑664, improper control of a resource during its lifecycle. The flaw allows an attacker who can influence the system to manipulate the allocation or release of resources, potentially resulting in resource exhaustion or unintended privilege elevation. This type of weakness can compromise system reliability, deny service, or create broader access if the affected resource is critical to security operations.
Affected Systems
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) are all affected. The precise affected versions are not enumerated in the advisory, so any installations of these products that have not been updated with the hardening release are vulnerable.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity, while the EPSS score is lower than 1%, suggesting a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. If exploited, an attacker would need sufficient access to influence resource handling—likely via privileged commands or misconfigurations—rather than a remote code execution vector. To date, there is no evidence of active exploitation.
OpenCVE Enrichment