CVE-2026-20330
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20330 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.34%
- CWE
- CWE-707
- Published
- 2026-09-16
- Last modified
- 2026-09-18
Affected products
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Weakness type
Related vulnerabilities
- CVE-2024-10915 — D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
- CVE-2024-10914 — D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
- CVE-2023-46689 — Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to pote
- CVE-2023-42773 — Improper neutralization in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to po
- CVE-2026-76443 — Cisco Secure Email Gateway Security Hardening Release
- CVE-2026-18613 — GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection
- CVE-2026-5002 — PromtEngineer localGPT LLM Prompt server.py _route_using_overviews injection
- CVE-2025-11445 — Kilo Code Prompt ClineProvider.ts ClineProvider injection