CVE-2026-20332: Cisco ASA, FTD, and FMC hardening: Improper Access Control Vulnerabilities

P1 — URGENTCISCO PSIRTADVISORY SIR: CRITICALDIRECT EXPLOITATION: NOT REPORTEDRELATED CVE EXPLOITATION: REPORTED

Quick Answer

Cisco published a Critical-rated advisory that includes CVE-2026-20332, affecting Cisco Secure Firewall ASA / FTD / FMC under the live advisory's conditions. Cisco does not separately state a CVE-specific Security Impact Rating (SIR); Common Vulnerability Scoring System (CVSS) base 9.9 (Critical). Confirm the exact platform, release, feature, and exposure; preserve relevant evidence; then follow Cisco's CVE-specific First Fixed guidance. Cisco reported no direct malicious use for this CVE at the last check; the advisory also identifies related CVEs with known-exploitation context (CVE-2026-20079, CVE-2026-20316). That status and absence from CISA KEV are time-bounded and do not prove exploitation has never occurred.

Fix Or Immediate Action

What to do now: Confirm the affected product, release, and configuration. Cisco provides no workaround; reduce exposure where operationally feasible. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.

Open the live Cisco advisory

Last verified: 2026-09-17 UTC from Cisco's advisory and CSAF record. Recheck both the affected-products and fixed-software sections before a production change.

Context

Scope And Impact In Plain Language

Who should check: Anyone who manages Cisco Secure Firewall ASA / FTD / FMC.

When this applies: These vulnerabilities affect the following Cisco products, regardless of device configuration: Secure Firewall ASA Software Secure FTD Software Secure FMC Software For information about which Cisco software releases are vulnerable, see the Fixed Software section of this advisory.

What could happen: An attacker may be able to bypass a security rule and reach data, systems, or administrative functions that should be blocked.

Not sure? Find the exact product, platform, and version in the management interface or CLI, then compare them with this CVE's affected-products section in Cisco's live advisory.

Status At A Glance

Product scopeCisco Secure Firewall ASA / FTD / FMC
CVECVE-2026-20332
TechGeeks response tierP1 — urgent
PublicationNew final Cisco advisory
First published2026-09-16T16:00:00+00:00
Last updated2026-09-16T16:00:00+00:00
Cisco advisory SIRCritical
CVE-specific Cisco SIRNot separately stated
CVSS base score / severity9.9 — Critical
CVSS vectorCVSS v3.1 — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV at last checkNo — this is separate from Cisco severity and is not proof of no exploitation.
Cisco exploitation statementExcept as otherwise noted previously, the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.

What Happened

CVE-2026-20332 9.0 CWE-284 Improper access control (covers authorization, authentication, privileges, and bypasses)1

Affected Scope

These vulnerabilities affect the following Cisco products, regardless of device configuration: Secure Firewall ASA Software Secure FTD Software Secure FMC Software For information about which Cisco software releases are vulnerable, see the Fixed Software section of this advisory.

Match the exact hardware or virtual platform, installed train, patch level, enabled service, role, and management or data-plane exposure. A Cisco product-family name alone does not establish applicability.

Steps

What To Do Now

  1. Confirm. Inventory Cisco Secure Firewall ASA / FTD / FMC and record platform, exact release, patch level, enabled feature, role, and exposure.
  2. Preserve. Save UTC context plus off-device authentication, management, firewall, network, endpoint, and SIEM evidence before logs rotate or a disruptive change removes context.
  3. Scope. Compare each asset with the live Cisco advisory, including configuration prerequisites and exclusions.
  4. Reduce exposure. Cisco documents no workaround for this CVE. Use only supported exposure controls while preparing the permanent fix.
  5. Remediate. Confirm the affected product, release, and configuration. Cisco provides no workaround; reduce exposure where operationally feasible. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.
  6. Validate. Confirm the resulting version, service health, logging, expected access, an expected denial, failover or cluster state, and representative dependent workflows.
  7. Escalate. If evidence or exposure creates concern, open incident response and Cisco TAC recovery work rather than treating patch completion as proof of trust.

Fixed Releases And Mitigation

Permanent Fix

Vendor-directed fix path: Confirm the affected product, release, and configuration. Cisco provides no workaround; reduce exposure where operationally feasible. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.

Cisco method: Use the live advisory's CVE-specific First Fixed Release table.

Software familyInstalled trainFirst Fixed / migration guidanceVendor note
Asa9.16 and earlier9.16.4.103—
Asa9.189.18.4.94—
Asa9.209.20.4.49—
Asa9.229.22.3.26—
Asa9.239.23.1.47—
Asa9.249.24.1.26—
Ftd And Fmc7.0 and earlier7.0.10—
Ftd And Fmc7.27.2.12—
Ftd And Fmc7.47.4.8—
Ftd And Fmc7.67.6.6—
Ftd And Fmc7.77.7.13—
Ftd And Fmc10.010.0.2—
Ftd And Fmc10.110.1.0—

Vendor baseline note: For the earliest fix for a specific advisory, platform, and installed release, Cisco directs customers to Cisco Software Checker.

These rows reproduce the normalized First Fixed or migration guidance from this advisory's own fixed-software table. Confirm the exact product, platform, release, and entitlement in Cisco's live Software Checker before production changes.

Workaround Or Temporary Mitigation

No vendor workaround is documented for CVE-2026-20332. Use supported exposure controls only as temporary risk reduction while preparing the permanent software fix.

Important boundary: A workaround, ACL, exposure reduction, or service restriction can reduce risk while the update is prepared, but it does not patch the vulnerable code, prove every attack path is closed, or erase an earlier compromise.

Investigation And Recovery

Review management authentication, account and privilege changes, API and web requests, configuration changes, crashes or restarts, resource pressure, and relevant external network telemetry for the vulnerable period. Preserve original evidence and follow Cisco TAC or incident-response guidance for containment, credential rotation, trusted rebuild, or service restoration when findings warrant it.

Notes

Exploitation Evidence

Cisco's exact status at the last check: Except as otherwise noted previously, the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.

This CVE was not present in the TechGeeks CISA KEV snapshot at the last check. Cisco's 'not aware' statement and absence from KEV are time-bounded evidence, not claims that exploitation is impossible or has never happened. Severity and exploitation status remain separate signals.

Cisco Score Source Difference

Cisco's live advisory Details table and downloadable structured CSAF record currently show different base scores for this CVE: advisory table 9; CSAF 9.9. This notice displays the structured CSAF score and vector while preserving the difference here. Recheck both Cisco sources when triaging; Cisco's advisory SIR—and a CVE-specific SIR when explicitly stated—remain separate vendor priority signals.

Validation And Boundaries

This notice is documentation-backed. TechGeeks did not reproduce the exploit or independently test every fixed build. It does not prove that all members of the product family are affected, that the activity is widespread, that a clean indicator search excludes compromise, or that an update restored trust. Cisco's live advisory controls affected and fixed release information.

Related TechGeeks Resources

References

Wrap-Up

Record whether CVE-2026-20332 applies. If it does, assign an owner and deadline appropriate to the Critical Cisco advisory SIR, preserve the evidence, complete Cisco's remediation, and document the validated result.

Correction policy: A material Cisco revision to scope, severity, exploitation status, workarounds, fixed software, or recovery guidance triggers an update and a new verification date.