CVE-2026-20154: Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software Logging Denial of Service
Quick Answer
Cisco published a High-rated advisory that includes CVE-2026-20154, affecting Cisco Secure Firewall ASA / FTD under the live advisory's conditions. Cisco does not separately state a CVE-specific Security Impact Rating (SIR); Common Vulnerability Scoring System (CVSS) base 8.6 (High). Confirm the exact platform, release, feature, and exposure; preserve relevant evidence; then follow Cisco's CVE-specific First Fixed guidance. Cisco reported no public announcement or malicious use for this CVE at the last check. That status and absence from CISA KEV are time-bounded and do not prove exploitation has never occurred.
Fix Or Immediate Action
What to do now: Confirm the affected product, release, and configuration. Apply Cisco's documented workaround as temporary risk reduction. Enter the exact installed product, platform, and release in Cisco Software Checker and upgrade to the returned First Fixed release. The CVE-specific live advisory and Cisco Software Checker result control the First Fixed release; any combined hardening baseline is supplemental only.
Last verified: 2026-09-17 UTC from Cisco's advisory and CSAF record. Recheck both the affected-products and fixed-software sections before a production change.
Context
Scope And Impact In Plain Language
Who should check: Anyone who manages Cisco Secure Firewall ASA / FTD.
When this applies: This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco Secure Firewall ASA Software or Cisco Secure FTD Software and have syslog logging enabled for message 419002. Logging message 419002 is enabled by default when logging is enabled globally. For information about which Cisco software releases are vulnerable, see the Fixed Software section of this advisory. Determine the Device Configuration To determine whether a device is affected by this vulnerability, use the following steps. 1. Use the show logging | include syslog logging command on the device CLI to verify if syslog logging is enabled globally. If the output of this command includes enabled, as shown in the following example, syslog logging is enabled globally. Proceed to Step 2. ASAv1# show logging | include syslog Syslog logging: enabled If the output indicates that logging is disabled, the device is not affected. 2. Use the show logging message 419002 command to determine if logging is specifically enabled for syslog message 419002. If the output of this command shows that logging is enabled for syslog message 419002, note the default level that the device uses when logging this message. The following example output shows that syslog message 419002 is enabled at default level warnings. Proceed to Step 3. ASA# show logging message 419002 syslog 419002: default-level warnings (enabled),standby logging (disabled) If logging for this message is disabled, the device is not affected. 3. Use the show logging | include logging: level command to determine if logging to any log destination is enabled and confirm the corresponding logging level. See the live Cisco advisory for the complete vendor text.
What could happen: An attacker may be able to crash, restart, or overload the affected service, causing an outage or loss of availability.
Not sure? Find the exact product, platform, and version in the management interface or CLI, then compare them with this CVE's affected-products section in Cisco's live advisory.
Status At A Glance
| Product scope | Cisco Secure Firewall ASA / FTD |
|---|---|
| CVE | CVE-2026-20154 |
| TechGeeks response tier | P1 — urgent |
| Publication | New final Cisco advisory |
| First published | 2026-09-16T16:00:00+00:00 |
| Last updated | 2026-09-16T16:00:00+00:00 |
| Cisco advisory SIR | High |
| CVE-specific Cisco SIR | Not separately stated |
| CVSS base score / severity | 8.6 — High |
| CVSS vector | CVSS v3.1 — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| CISA KEV at last check | No — this is separate from Cisco severity and is not proof of no exploitation. |
| Cisco exploitation statement | The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory. |
What Happened
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.
Affected Scope
This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco Secure Firewall ASA Software or Cisco Secure FTD Software and have syslog logging enabled for message 419002. Logging message 419002 is enabled by default when logging is enabled globally. For information about which Cisco software releases are vulnerable, see the Fixed Software section of this advisory. Determine the Device Configuration To determine whether a device is affected by this vulnerability, use the following steps. 1. Use the show logging | include syslog logging command on the device CLI to verify if syslog logging is enabled globally. If the output of this command includes enabled, as shown in the following example, syslog logging is enabled globally. Proceed to Step 2. ASAv1# show logging | include syslog Syslog logging: enabled If the output indicates that logging is disabled, the device is not affected. 2. Use the show logging message 419002 command to determine if logging is specifically enabled for syslog message 419002. If the output of this command shows that logging is enabled for syslog message 419002, note the default level that the device uses when logging this message. The following example output shows that syslog message 419002 is enabled at default level warnings. Proceed to Step 3. ASA# show logging message 419002 syslog 419002: default-level warnings (enabled),standby logging (disabled) If logging for this message is disabled, the device is not affected. 3. Use the show logging | include logging: level command to determine if logging to any log destination is enabled and confirm the corresponding logging level. See the live Cisco advisory for the complete vendor text.
Match the exact hardware or virtual platform, installed train, patch level, enabled service, role, and management or data-plane exposure. A Cisco product-family name alone does not establish applicability.
Steps
What To Do Now
- Confirm. Inventory Cisco Secure Firewall ASA / FTD and record platform, exact release, patch level, enabled feature, role, and exposure.
- Preserve. Save UTC context plus off-device authentication, management, firewall, network, endpoint, and SIEM evidence before logs rotate or a disruptive change removes context.
- Scope. Compare each asset with the live Cisco advisory, including configuration prerequisites and exclusions.
- Reduce exposure. Evaluate and apply Cisco's temporary workaround in the highlighted panel below; it does not replace the permanent fix.
- Remediate. Confirm the affected product, release, and configuration. Apply Cisco's documented workaround as temporary risk reduction. Enter the exact installed product, platform, and release in Cisco Software Checker and upgrade to the returned First Fixed release. The CVE-specific live advisory and Cisco Software Checker result control the First Fixed release; any combined hardening baseline is supplemental only.
- Validate. Confirm the resulting version, service health, logging, expected access, an expected denial, failover or cluster state, and representative dependent workflows.
- Escalate. If evidence or exposure creates concern, open incident response and Cisco TAC recovery work rather than treating patch completion as proof of trust.
Fixed Releases And Mitigation
Permanent Fix
Vendor-directed fix path: Confirm the affected product, release, and configuration. Apply Cisco's documented workaround as temporary risk reduction. Enter the exact installed product, platform, and release in Cisco Software Checker and upgrade to the returned First Fixed release. The CVE-specific live advisory and Cisco Software Checker result control the First Fixed release; any combined hardening baseline is supplemental only.
Cisco method: Use Cisco Software Checker with the exact installed product, platform, and release to obtain the advisory-specific First Fixed release; the combined September hardening baseline is also recorded.
No compact per-CVE fixed-release table is reproduced here because Cisco may use different First Fixed values by CVE and software train. Use this CVE's live advisory table or Cisco Software Checker; do not infer a fixed release from a combined hardening baseline or another Cisco notice.
Workaround Or Temporary Mitigation
There is a workaround that addresses this vulnerability. Rate limit in Cisco Secure Firewall ASA Software or Cisco Secure FTD Software using the methods described in the following sections. Cisco Secure Firewall ASA Software For devices that are running Cisco Secure Firewall ASA Software, append in global configuration mode and manually rate limit using the logging rate-limit 100 1 message 419002 command. In the following example, message 419002 is limited to a rate of 100 messages per second, which will prevent successful exploitation of this vulnerability: ASA(config)# logging rate-limit 100 1 message 419002 Cisco Secure FTD Software For devices that are running Cisco Secure FTD Software, use one of the following options: Choose Secure Firewall Management Center (FMC) > Devices > Platform Settings > Rate Limit > Syslog Level and deploy the appropriate policies. For more information, see Configure Logging on FTD via FMC. Choose Firewall Device Manager (FTD) > Device > System Settings > Logging and rate limit message 419002 to 100 messages per second. For more information, see Configure and Verify Syslog in Firepower Device Manager. While this workaround has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer deployment scenarios and limitations. Customers should not deploy any workarounds or mitigations before first evaluating the applicability to their own environment and any impact to such environment.
Important boundary: A workaround, ACL, exposure reduction, or service restriction can reduce risk while the update is prepared, but it does not patch the vulnerable code, prove every attack path is closed, or erase an earlier compromise.
Investigation And Recovery
Review management authentication, account and privilege changes, API and web requests, configuration changes, crashes or restarts, resource pressure, and relevant external network telemetry for the vulnerable period. Preserve original evidence and follow Cisco TAC or incident-response guidance for containment, credential rotation, trusted rebuild, or service restoration when findings warrant it.
Notes
Exploitation Evidence
Cisco's exact status at the last check: The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
This CVE was not present in the TechGeeks CISA KEV snapshot at the last check. Cisco's 'not aware' statement and absence from KEV are time-bounded evidence, not claims that exploitation is impossible or has never happened. Severity and exploitation status remain separate signals.
Validation And Boundaries
This notice is documentation-backed. TechGeeks did not reproduce the exploit or independently test every fixed build. It does not prove that all members of the product family are affected, that the activity is widespread, that a clean indicator search excludes compromise, or that an update restored trust. Cisco's live advisory controls affected and fixed release information.
Related TechGeeks Resources
- TechGeeks Security Notice Center
- All Security Notices
- What to Do When a Device Hits CISA KEV
- Router CVE Exposure, Version, and Mitigation Checklist
- IoT Firmware Update and End-of-Support Checklist
- Live Protect and Runtime Vulnerability Shielding
References
Wrap-Up
Record whether CVE-2026-20154 applies. If it does, assign an owner and deadline appropriate to the High Cisco advisory SIR, preserve the evidence, complete Cisco's remediation, and document the validated result.
Correction policy: A material Cisco revision to scope, severity, exploitation status, workarounds, fixed software, or recovery guidance triggers an update and a new verification date.

