« Back to list

Cisco

Cisco Secure Firewall Threat Defense: vulnerabilities and CVEs

Cisco Secure Firewall Threat Defense has 299 published vulnerabilities, 47 of them in the last 12 months. 6 are rated critical and 13 are listed by CISA as actively exploited.

CVEs299
Last 12 months47
Critical6
Actively exploited13

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-20349High (8.6)1.0%⚠ Active exploitationAug 11, 2026
This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected…
CVE-2025-20333Critical (9.9)71%⚠ Active exploitationSep 25, 2025
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute…
CVE-2025-20362High (8.6)87%⚠ Active exploitationSep 25, 2025
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362.…
CVE-2024-20481Medium (5.8)16%⚠ Active exploitationOct 23, 2024
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a…
CVE-2024-20353High (8.6)71%⚠ Active exploitationApr 24, 2024
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the…
CVE-2024-20359Medium (6)19%⚠ Active exploitationApr 24, 2024
A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)…
CVE-2020-3259High (7.5)72%⚠ Active exploitationMay 6, 2020
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory…
CVE-2023-44487High (7.5)100%⚠ Active exploitationOct 10, 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-20269Critical (9.1)25%⚠ Active exploitationSep 6, 2023
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute…
CVE-2021-44228Critical (10)100%⚠ Active exploitationDec 10, 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…
CVE-2020-3580Medium (6.1)86%⚠ Active exploitationOct 21, 2020
Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct…
CVE-2020-3452High (7.5)100%⚠ Active exploitationJul 22, 2020
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory…
CVE-2018-0296High (7.5)100%⚠ Active exploitationJun 7, 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-20290Medium (5.8)0.19%—Sep 16, 2026
A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine…
CVE-2026-20250High (8.6)0.55%—Sep 16, 2026
A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series…
CVE-2026-20248Medium (6.8)0.34%—Sep 16, 2026
A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote…
CVE-2026-20222High (7.4)0.17%—Sep 16, 2026
A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker…
CVE-2026-20154High (8.6)0.40%—Sep 16, 2026
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an…
CVE-2026-20135High (8.6)0.46%—Sep 16, 2026
A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a…
CVE-2026-20120Medium (5.8)0.41%—Sep 16, 2026
A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could…
CVE-2026-20349High (8.6)1.0%⚠ Active exploitationAug 11, 2026
This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected…
CVE-2026-20012High (8.6)0.35%—Mar 25, 2026
A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat…
CVE-2026-20064Medium (6.5)0.10%—Mar 4, 2026
A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition. This…
CVE-2026-20025Medium (6.8)0.16%—Mar 4, 2026
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a…
CVE-2026-20024Medium (5.7)0.19%—Mar 4, 2026
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a…
CVE-2026-20023Medium (6.5)0.15%—Mar 4, 2026
A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to…
CVE-2026-20022Medium (6.5)0.19%—Mar 4, 2026
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in…
CVE-2026-20021Medium (4.3)0.20%—Mar 4, 2026
A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, adjacent attacker to exhaust…
CVE-2026-20020Medium (5.7)0.25%—Mar 4, 2026
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in…
CVE-2026-20016Medium (6.7)0.33%—Mar 4, 2026
A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying…
CVE-2026-20106Medium (5.3)0.32%—Mar 4, 2026
A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an…
CVE-2026-20105High (7.7)0.32%—Mar 4, 2026
A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote…
CVE-2026-20103High (8.6)0.35%—Mar 4, 2026
A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote…
CVE-2026-20102Medium (6.1)0.26%—Mar 4, 2026
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a…
CVE-2026-20101High (8.6)0.35%—Mar 4, 2026
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly,…
CVE-2026-20100High (7.7)0.28%—Mar 4, 2026
A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an…
CVE-2026-20073Medium (5.8)0.38%—Mar 4, 2026
A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should be…
CVE-2026-20070Medium (6.1)0.26%—Mar 4, 2026
This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by persuading a user to follow a link to a malicious website that is designed to…
CVE-2026-20069Medium (4.3)0.27%—Mar 4, 2026
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote…
CVE-2026-20068Medium (5.8)0.41%—Mar 4, 2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption…
CVE-2026-20067Medium (5.8)0.45%—Mar 4, 2026
This vulnerability is due to incomplete error checking when parsing the Multicast DNS fields of the HTTP header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an established…
CVE-2026-20066Medium (5.8)0.45%—Mar 4, 2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption…
CVE-2026-20065Medium (5.8)0.37%—Mar 4, 2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1499 Endpoint Denial of Service3
  3. T1078 Valid Accounts2
  4. T1040 Network Sniffing1
  5. T1059 Command and Scripting Interpreter1
  6. T1110 Brute Force1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

📰 Related news

Other products by Cisco