Skip to content
CiscoCVE-2026-20332

Cisco Secure Firewall: improper access control

Critical9.9CVE-2026-20332 · Published Sep 16, 2026 · updated Sep 18, 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.   The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Product
<= 9.16.1No fix yet
<= 9.16.1.28No fix yet
<= 9.16.2No fix yet
<= 9.16.2.3No fix yet
Cisco Secure Firewall Management Center (FMC)
Product
<= 7.0.0No fix yet
<= 7.0.0.1No fix yet
<= 7.0.1No fix yet
<= 7.0.1.1No fix yet
Cisco Secure Firewall Threat Defense (FTD) Software
Product
<= 7.0.0.1No fix yet
<= 7.0.1No fix yet
<= 7.0.1.1No fix yet
<= 7.0.2No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco ISE Passive Identity Connector: SQL injection
Medium4.9Sep 16
Cisco ISE Passive Identity: authenticated, remote attacker could conduct an SQL...
Medium4.9Sep 16
Cisco ISE Passive Identity: authenticated, remote attacker could conduct an SQL...
Medium4.9Sep 16
Cisco ISE Passive Identity Connector: authentication bypass
Critical10.0Sep 16
Cisco ISE Passive Identity Connector: XML external entity
Medium4.9Sep 16
Cisco ISE Passive Identity Connector: missing authentication
Medium5.3Sep 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.