CVE-2026-20106
Description
A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition requiring a manual reboot. This vulnerability is due to trusting user input without validation. An attacker could exploit this vulnerability by sending crafted packets to the Remote Access SSL VPN server. A successful exploit could allow the attacker to cause the device to stop responding, resulting in a DoS condition.
Affected products
2- cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*Range: >=6.4.0,<7.0.9
- cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*Range: >=9.12.1,<9.16.4.85
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.