High severity8.6NVD Advisory· Published Mar 4, 2026· Updated Apr 16, 2026
CVE-2026-20101
CVE-2026-20101
Description
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could exploit this vulnerability by sending crafted SAML messages to the SAML service. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Affected products
2- cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*Range: >=6.4.0,<7.0.9
- cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*Range: >=9.12.1,<9.16.4.85
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.