CVE-2026-20329
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20329 are related to issues concerning improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- CWE
- CWE-703
- Published
- 2026-09-16
- Last modified
- 2026-09-17
Affected products
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Weakness type
Related vulnerabilities
- CVE-2023-0397 — DoS: Invalid Initialization in le_read_buffer_size_complete
- CVE-2021-3329 — DOS: Incorrect handling of the initial HCI ACL_MTU handshake packet leads to crash of bluetooth host layer
- CVE-2024-39815 — Vonets WiFi Bridges Improper Check or Handling of Exceptional Conditions
- CVE-2021-23859 — Denial of Service and Authentication Bypass Vulnerability in multiple Bosch products
- CVE-2019-5031 — An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, ver
- CVE-2023-5038 — Unauthenticated DoS
- CVE-2022-22265 — An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary m
- CVE-2024-21525 — All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the