CVE-2026-20336
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20336 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-664
- Published
- 2026-09-16
- Last modified
- 2026-09-17
Affected products
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Weakness type
Related vulnerabilities
- CVE-2022-27518 — Unauthenticated remote arbitrary code execution
- CVE-2020-3175 — Cisco MDS 9000 Series Multilayer Switches Denial of Service Vulnerability
- CVE-2022-20856 — Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Mobility Denial of Service Vulnerability
- CVE-2026-20274 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-20353 — Cisco Secure Email Gateway Security Hardening Release
- CVE-2022-2048 — In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug
- CVE-2022-2191 — In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffer
- CVE-2023-44288 — Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnera