TL;DR
Cisco fixed 18 Cisco Secure Firewall vulnerabilities on September 16, 2026. Several are critical and allow remote code execution as root. The flaws span Firewall Management Center, ASA, and Threat Defense software.
- Total: 18 CVEs
- Severity: 8 Critical · 10 High
- Actively exploited: None confirmed
- Highest severity: 9.9 (Critical · CVSSv3) — CVE-2026-20324
- Action: Apply the latest security updates now
Track every Cisco CVE the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-20324 | 9.9 | Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution | Not exploited |
| CVE-2026-20329 | 9.9 | Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling | Not exploited |
| CVE-2026-20330 | 9.9 | Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization | Not exploited |
| CVE-2026-20332 | 9.9 | Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control | Not exploited |
| CVE-2026-20242 | 9.8 | Secure Firewall Management Center Software Java Deserialization Remote Code Execution | Not exploited |
| CVE-2026-20331 | 9.6 | Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure | Not exploited |
| CVE-2026-20341 | 9.1 | Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution | Not exploited |
| CVE-2026-76420 | 9 | Secure Firewall Management Center Software Impersonated sftunnel Connection | Not exploited |
Why these Cisco Secure Firewall vulnerabilities matter
Firewalls guard the edge of nearly every enterprise network. A root compromise there breaks that first line of defense. These Cisco Secure Firewall vulnerabilities include several paths to full device takeover.
Five separate advisories landed together. Many flaws carry CVSS scores of 9.0 or higher. Cisco released free software updates for all of them.
How the attacks work
The most severe flaws
The top issue is CVE-2026-20242, a CVSS 9.8 Java deserialization bug. Per Cisco, an unauthenticated attacker can send a crafted Java byte stream and “execute arbitrary commands as root.” A related sftunnel flaw, CVE-2026-20324, scores 9.9 and also grants root.
The joint hardening release adds more critical bugs. CVE-2026-20329, CVE-2026-20330, and CVE-2026-20332 each rate 9.9. They affect ASA and Threat Defense alongside FMC.
Other patched issues
The advisories also cover SQL injection, privilege escalation, and information disclosure. CVE-2026-20344 is a SQL injection flaw rated 8.8. Several others allow authenticated attackers to raise their privileges or read sensitive data.
Affected versions and exploitation status
The bugs affect specific releases of FMC, ASA, and Threat Defense software. Cisco lists exact fixed builds in each advisory. Importantly, Cisco PSIRT “is not aware of any public announcements or malicious use” of these flaws. No proof-of-concept has been confirmed.
Patch and mitigation steps
Upgrade to a fixed release without delay. There are no workarounds for most of these Cisco Secure Firewall vulnerabilities. Start with the unauthenticated root RCE bugs in the Java deserialization advisory and the sftunnel root RCE advisory. Next, review the joint ASA, FTD, and FMC hardening release. Then apply the two multi-flaw FMC bulletins, tracked as cisco-sa-fmc2-multivulns and cisco-sa-fmc-mulivulns. Finally, restrict management access to trusted hosts.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!