Vulnerability threat dossier

CVE-2026-20332

CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) Software

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.   The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

VTP deterministic threat20.6of 100 · CVSS excluded

VTP analyst assessment

Reported exploitation of Cisco Secure Firewall authorization flaw

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence60%
Public exploitation · VTP factREPORTED

Assessment

SecurityWeek reports exploitation of CVE-2026-20332 among Cisco firewall-management vulnerabilities. The CVE is an improper authorization flaw in Cisco Secure Firewall ASA Software, but the supplied material does not state the exact exploitation path.

Why it matters

  • Firewall and firewall-management systems control network access, so authorization failures can have broad operational impact.
  • Cisco issued a hardening release for multiple internally discovered vulnerabilities.

Evidence

2 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The exploitation report does not provide CVE-specific mechanics or independent corroboration.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use affected Cisco Secure Firewall ASA Software, apply Cisco's hardening release and review privileged administrative activity around the advisory period.

AI baseline history (3)
  1. BASELINE ASSESSED
    Reported exploitation of Cisco Secure Firewall authorization flawgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Cisco ASA authorization flawgpt-5.6-terra · low
  3. BASELINE ASSESSED
    CVE-specific impact cannot be establishedgpt-5.6-terra · low
Technical severityCRITICALCVSS 9.9 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0023th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.00; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

CERT ADVISORYNew CERT advisory
VENDOR ADVISORYNew vendor advisory
03

Claim provenance

Evidence and source independence

4publications detected
4underlying evidence chains

2 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:3efb05e0937b9d9a104b4559ec7e82f05f85a2d234a15475c35932ae847f0393ACTIVE
Evidence
04

Event history

Threat timeline

  1. 12:1717 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 00:0017 Sept
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-20332.

  3. 16:0016 Sept
    VENDOR ADVISORY

    New vendor advisory

    Cisco Product Security Incident Response Team published evidence linked to CVE-2026-20332.

05

Original publications

Source record

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.   These vulnerabilities were found during internal testing. Two of them are known to be actively exploited. For more information, see the following advisories: Cisco Secure Firewall Management Center Software Static Credential Vulnerability and Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability . To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories .  <br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20329,CVE-2026-20330,CVE-2026-20331,CVE-2026-20332,CVE-2026-20333,CVE-2026-20334,CVE-2026-20335,CVE-2026-20336

CVE-2026-20329CVE-2026-20330CVE-2026-20331CVE-2026-20332CVE-2026-20333CVE-2026-20334CVE-2026-20335CVE-2026-20336
Separate evidence group
Original

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution. The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek .

CVE-2026-20079CVE-2026-20282CVE-2026-20283CVE-2026-20284CVE-2026-20316CVE-2026-20332
Separate evidence group
Original

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker

CVE-2026-20130CVE-2026-20176CVE-2026-20192CVE-2026-20194CVE-2026-20211CVE-2026-20234CVE-2026-20237CVE-2026-20242CVE-2026-20282CVE-2026-20283CVE-2026-20284CVE-2026-20287CVE-2026-20305CVE-2026-20306CVE-2026-20307CVE-2026-20322CVE-2026-20324CVE-2026-20325CVE-2026-20326CVE-2026-20329CVE-2026-20330CVE-2026-20331CVE-2026-20332CVE-2026-20333CVE-2026-20334CVE-2026-20335CVE-2026-20336CVE-2026-20340CVE-2026-20341CVE-2026-20342CVE-2026-20343CVE-2026-20344CVE-2026-20353CVE-2026-20360CVE-2026-20361CVE-2026-76409CVE-2026-76412CVE-2026-76413CVE-2026-76420CVE-2026-76423CVE-2026-76424CVE-2026-76425CVE-2026-76426CVE-2026-76427CVE-2026-76428CVE-2026-76440CVE-2026-76441CVE-2026-76442CVE-2026-76443CVE-2026-76460CVE-2026-76461
Separate evidence group
Original

Multiples vulnérabilités dans les produits Cisco (17 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits Cisco. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Cisco indique que la vulnérabilité CVE-2026-76460 est...

CVE-2026-20130CVE-2026-20135CVE-2026-20154CVE-2026-20176CVE-2026-20192CVE-2026-20194CVE-2026-20211CVE-2026-20222CVE-2026-20234CVE-2026-20237CVE-2026-20242CVE-2026-20247CVE-2026-20249CVE-2026-20250CVE-2026-20282CVE-2026-20283CVE-2026-20284CVE-2026-20287CVE-2026-20295CVE-2026-20300CVE-2026-20305CVE-2026-20306CVE-2026-20307CVE-2026-20322CVE-2026-20323CVE-2026-20324CVE-2026-20325CVE-2026-20326CVE-2026-20329CVE-2026-20330CVE-2026-20331CVE-2026-20332CVE-2026-20333CVE-2026-20334CVE-2026-20335CVE-2026-20336CVE-2026-20340CVE-2026-20341CVE-2026-20342CVE-2026-20343CVE-2026-20344CVE-2026-20352CVE-2026-20360CVE-2026-20361CVE-2026-76409CVE-2026-76412CVE-2026-76413CVE-2026-76420CVE-2026-76423CVE-2026-76424CVE-2026-76425CVE-2026-76426CVE-2026-76427CVE-2026-76428CVE-2026-76460
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score20.6vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.06 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency6 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.9 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-284
CPE records
0
Deterministic history records
11
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.