CVE-2026-20100 is a denial-of-service vulnerability in the LUA interpreter of Cisco Secure Firewall ASA and FTD Software's Remote Access SSL VPN feature. An authenticated, remote attacker can exploit this by sending crafted HTTP packets, causing the device to reload unexpectedly. This vulnerability has a CVSS score of 7.7 (High), indicating a network-based attack with low complexity, requiring authenticated user privileges, and resulting in a complete loss of availability. It does not affect management or MUS interfaces. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting limited public attention at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.12.1CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.12.1:*:*:*:*:*:*:* | ||
9.12.1.2CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.12.1.2:*:*:*:*:*:*:* | ||
9.12.1.3CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.12.1.3:*:*:*:*:*:*:* | ||
9.12.2CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.12.2:*:*:*:*:*:*:* | ||
9.12.2.1CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.12.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.