CVE-2026-20106 is a denial-of-service vulnerability affecting Cisco Secure Firewall ASA and FTD Software, specifically within their Remote Access SSL VPN, HTTP management, and MUS functionalities. An unauthenticated, remote attacker can exploit this by sending crafted packets, leading to memory exhaustion and a device crash requiring a manual reboot. The vulnerability has a CVSS score of 5.3 (Medium), indicating a low attack complexity and no user interaction required, with the primary impact being a denial of service. The EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild. Currently, there is no known active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, further indicating a low level of immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.12.1, < 9.16.4.85CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.17.1, < 9.18.4.66CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.19.1, < 9.20.4CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.22.1.1, < 9.22.2.4CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.23.1, < 9.23.1.7CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.