Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20336 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Improper control of a system resource through its lifetime leading to potential resource misuse or exhaustion
Action: Apply Patch
AI Analysis

Impact

The vulnerability described in CVE‑2026‑20336 centers on CWE‑664, improper control of a resource during its lifecycle. The flaw allows an attacker who can influence the system to manipulate the allocation or release of resources, potentially resulting in resource exhaustion or unintended privilege elevation. This type of weakness can compromise system reliability, deny service, or create broader access if the affected resource is critical to security operations.

Affected Systems

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) are all affected. The precise affected versions are not enumerated in the advisory, so any installations of these products that have not been updated with the hardening release are vulnerable.

Risk and Exploitability

The CVSS score is 8.8, indicating high severity, while the EPSS score is lower than 1%, suggesting a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. If exploited, an attacker would need sufficient access to influence resource handling—likely via privileged commands or misconfigurations—rather than a remote code execution vector. To date, there is no evidence of active exploitation.

Generated by OpenCVE AI on September 17, 2026 at 22:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Cisco Secure Firewall, ASA, and FMC firmware or software to the latest hardening release that resolves the resource lifetime management issues, following the guidance in Cisco’s Security Advisory.
  • Implement temporary mitigations recommended by Cisco, such as disabling high‑risk resource usage functions or applying configuration defaults until the patch is applied.
  • Enable detailed logging for resource allocation and monitor for abnormal resource usage patterns to detect potential abuse before it affects service availability.

Generated by OpenCVE AI on September 17, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco adaptive Security Appliance Software
Cisco secure Firewall Management Center
Cisco secure Firewall Threat Defense
Vendors & Products Cisco
Cisco adaptive Security Appliance Software
Cisco secure Firewall Management Center
Cisco secure Firewall Threat Defense

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20336 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Title Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Resource Lifetime Management Vulnerabilities
Weaknesses CWE-664
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Adaptive Security Appliance Software Secure Firewall Management Center Secure Firewall Threat Defense
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T19:10:51.077Z

Reserved: 2025-10-08T11:59:15.413Z

Link: CVE-2026-20336

cve-icon Vulnrichment

Updated: 2026-09-17T14:53:17.450Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:11.350

Modified: 2026-09-18T20:17:15.220

Link: CVE-2026-20336

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:07Z

Weaknesses
  • CWE-664

    Improper Control of a Resource Through its Lifetime