Skip to content

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability

Sec.Cloudapps.Cisco September 16, 2026

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. This advisory is available at the following link: This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories . In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 .

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition.

This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation.

Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.

This advisory is available at the following link:

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories . In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 .

Vulnerable Products This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco Secure Firewall ASA Software or Cisco Secure FTD Software and have syslog logging enabled for message 419002. Logging message 419002 is enabled by default when logging is enabled globally. For information which Cisco software releases are vulnerable, see the Fixed Software section of this advisory. Determine the Device Configuration To determine whether a device is affected by this vulnerability, use the following steps. 1. Use the show logging | include syslog logging command on the device CLI to verify if syslog logging is enabled globally. If the output of this command includes enabled , as shown in the following example, syslog logging is enabled globally. Proceed to Step 2. ASAv1# show logging | include syslog Syslog logging: enabled If the output indicates that logging is disabled, the device is not affected. 2. Use the show logging message 419002 command to determine if logging is specifically enabled for syslog message 419002. If the output of this command shows that logging is enabled for syslog message 419002, note the default level that the device uses when logging this message. The following example output shows that syslog message 419002 is enabled at default level warnings . Proceed to Step 3. ASA# show logging message 419002 syslog 419002: default-level warnings (enabled),standby logging (disabled) If logging for this message is disabled, the device is not affected. 3. Use the show logging | include logging: level command to determine if logging to any log destination is enabled and confirm the corresponding logging level. The following example output shows that logging is enabled for destination Console at level errors and for destination Buffer at level warnings : ASA# show logging | include logging: level Console logging: level errors , 301 messages logged Buffer logging: level warnings , 265964 messages logged If logging to any destination is enabled at the logging level that was confirmed for syslog message 419002 in Step 2 or higher, the device is affected. In the example in Step 3, logging to destination Buffer is configured to level warnings , which corresponds to the logging level for syslog message 419002 in the example in Step 2. The device in this example would be considered vulnerable. In the example in Step 3, logging to destination Console is configured at level errors , which is below the logging level for syslog message 419002 in the example in Step 2. If this were the only enabled logging destination on the device, syslog message 419002 would never be logged, and the device would not be considered vulnerable. Empty output of the show logging | include logging: level command indicates that the device is not affected. For more information on logging configuration, see the Logging chapter in CLI Book 1: Cisco Secure Firewall ASA Series General Operations CLI Configuration Guide, 9.24 , the Syslog section in the Cisco Secure Firewall Management Center Device Configuration Guide , or the Configuring System Logging Settings section in the Cisco Secure Firewall Device Manager Configuration Guide . Products Confirmed Not Vulnerable Only products listed in the Vulnerable Products section of this advisory are known to be affected by this vulnerability. Cisco has confirmed that this vulnerability does not affect Cisco Secure Firewall Management Center (FMC) Software.

This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco Secure Firewall ASA Software or Cisco Secure FTD Software and have syslog logging enabled for message 419002. Logging message 419002 is enabled by default when logging is enabled globally.

For information which Cisco software releases are vulnerable, see the Fixed Software section of this advisory.

Determine the Device Configuration

To determine whether a device is affected by this vulnerability, use the following steps.

1. Use the show logging | include syslog logging command on the device CLI to verify if syslog logging is enabled globally. If the output of this command includes enabled , as shown in the following example, syslog logging is enabled globally. Proceed to Step 2.

ASAv1# show logging | include syslog Syslog logging: enabled

If the output indicates that logging is disabled, the device is not affected.

2. Use the show logging message 419002 command to determine if logging is specifically enabled for syslog message 419002. If the output of this command shows that logging is enabled for syslog message 419002, note the default level that the device uses when logging this message. The following example output shows that syslog message 419002 is enabled at default level warnings . Proceed to Step 3.

ASA# show logging message 419002 syslog 419002: default-level warnings (enabled),standby logging (disabled)

If logging for this message is disabled, the device is not affected.

3. Use the show logging | include logging: level command to determine if logging to any log destination is enabled and confirm the corresponding logging level. The following example output shows that logging is enabled for destination Console at level errors and for destination Buffer at level warnings :

ASA# show logging | include logging: level Console logging: level errors , 301 messages logged Buffer logging: level warnings , 265964 messages logged

If logging to any destination is enabled at the logging level that was confirmed for syslog message 419002 in Step 2 or higher, the device is affected.

In the example in Step 3, logging to destination Buffer is configured to level warnings , which corresponds to the logging level for syslog message 419002 in the example in Step 2. The device in this example would be considered vulnerable.

In the example in Step 3, logging to destination Console is configured at level errors , which is below the logging level for syslog message 419002 in the example in Step 2. If this were the only enabled logging destination on the device, syslog message 419002 would never be logged, and the device would not be considered vulnerable.

Empty output of the show logging | include logging: level command indicates that the device is not affected.

For more information on logging configuration, see the Logging chapter in CLI Book 1: Cisco Secure Firewall ASA Series General Operations CLI Configuration Guide, 9.24 , the Syslog section in the Cisco Secure Firewall Management Center Device Configuration Guide , or the Configuring System Logging Settings section in the Cisco Secure Firewall Device Manager Configuration Guide .

Products Confirmed Not Vulnerable

Only products listed in the Vulnerable Products section of this advisory are known to be affected by this vulnerability.

Cisco has confirmed that this vulnerability does not affect Cisco Secure Firewall Management Center (FMC) Software.

There is a workaround that addresses this vulnerability. Rate limit in Cisco Secure Firewall ASA Software or Cisco Secure FTD Software using the methods described in the following sections. Cisco Secure Firewall ASA Software For devices that are running Cisco Secure Firewall ASA Software, append in global configuration mode and manually rate limit using the logging rate-limit 100 1 message 419002 command. In the following example, message 419002 is limited to a rate of 100 messages per second, which will prevent successful exploitation of this vulnerability: ASA(config)# logging rate-limit 100 1 message 419002 Cisco Secure FTD Software For devices that are running Cisco Secure FTD Software, use one of the following options: Choose Secure Firewall Management Center (FMC) > Devices > Platform Settings > Rate Limit > Syslog Level and deploy the appropriate policies. For more information, see Configure Logging on FTD via FMC . Choose Firewall Device Manager (FTD) > Device > System Settings > Logging and rate limit message 419002 to 100 messages per second. For more information, see Configure and Verify Syslog in Firepower Device Manager . While this workaround has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer deployment scenarios and limitations. Customers should not deploy any workarounds or mitigations before first evaluating the applicability to their own environment and any impact to such environment.

There is a workaround that addresses this vulnerability. Rate limit in Cisco Secure Firewall ASA Software or Cisco Secure FTD Software using the methods described in the following sections.

Cisco Secure Firewall ASA Software

For devices that are running Cisco Secure Firewall ASA Software, append in global configuration mode and manually rate limit using the logging rate-limit 100 1 message 419002 command.

In the following example, message 419002 is limited to a rate of 100 messages per second, which will prevent successful exploitation of this vulnerability:

ASA(config)# logging rate-limit 100 1 message 419002

Cisco Secure FTD Software

For devices that are running Cisco Secure FTD Software, use one of the following options:

Choose Secure Firewall Management Center (FMC) > Devices > Platform Settings > Rate Limit > Syslog Level and deploy the appropriate policies. For more information, see Configure Logging on FTD via FMC .

Choose Firewall Device Manager (FTD) > Device > System Settings > Logging and rate limit message 419002 to 100 messages per second. For more information, see Configure and Verify Syslog in Firepower Device Manager .

While this workaround has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer deployment scenarios and limitations. Customers should not deploy any workarounds or mitigations before first evaluating the applicability to their own environment and any impact to such environment.

Cisco considers any workarounds and mitigations (if applicable) to be temporary solutions until an upgrade to a fixed software release is available. To remediate this vulnerability and avoid future exposure as described in this advisory, Cisco strongly recommends that customers upgrade to the fixed software indicated in this advisory. Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software To help customers determine their exposure to vulnerabilities in Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software, Cisco provides the Cisco Software Checker . This tool identifies any Cisco security advisories that impact a specific software release and the earliest release that fixes the vulnerabilities that are described in each advisory (“First Fixed”). If applicable, the tool also returns the earliest release that fixes all the vulnerabilities that are described in all the advisories that the Software Checker identifies (“Combined First Fixed”). To use the tool, go to the Cisco Software Checker page and follow the instructions. Alternatively, use the following form to for vulnerabilities that affect a specific software release. To use the form, follow these steps: Choose which advisories the tool will -all advisories, only advisories with a Critical or High Security Impact Rating (SIR) , or only this advisory. Choose the appropriate software. Choose the appropriate platform. Enter a release number-for example, 9.20.3.4 for Cisco Secure Firewall ASA Software or 7.4.2 for Cisco Secure FTD Software. Click Check . For instructions on upgrading a Cisco Secure FTD device, see the appropriate Cisco Secure FMC upgrade guide .

Cisco considers any workarounds and mitigations (if applicable) to be temporary solutions until an upgrade to a fixed software release is available. To remediate this vulnerability and avoid future exposure as described in this advisory, Cisco strongly recommends that customers upgrade to the fixed software indicated in this advisory.

Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software

To help customers determine their exposure to vulnerabilities in Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software, Cisco provides the Cisco Software Checker . This tool identifies any Cisco security advisories that impact a specific software release and the earliest release that fixes the vulnerabilities that are described in each advisory (“First Fixed”). If applicable, the tool also returns the earliest release that fixes all the vulnerabilities that are described in all the advisories that the Software Checker identifies (“Combined First Fixed”).

To use the tool, go to the Cisco Software Checker page and follow the instructions. Alternatively, use the following form to for vulnerabilities that affect a specific software release. To use the form, follow these steps:

Choose which advisories the tool will -all advisories, only advisories with a Critical or High Security Impact Rating (SIR) , or only this advisory.

Choose the appropriate software.

Choose the appropriate platform.

Enter a release number-for example, 9.20.3.4 for Cisco Secure Firewall ASA Software or 7.4.2 for Cisco Secure FTD Software.

For instructions on upgrading a Cisco Secure FTD device, see the appropriate Cisco Secure FMC upgrade guide .

Exploitation and Public Announcements

The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.

The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.

This vulnerability was found during the resolution of a Cisco Technical Assistance Center (TAC) support case.

This vulnerability was found during the resolution of a Cisco Technical Assistance Center (TAC) support case.

Cisco Security Vulnerability Policy

To learn Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy . This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco. For additional information on Cisco's vulnerability management, disclosure cadence, and software patching strategy, see Cisco's Transition to a Risk-Based Vulnerability Disclosure Model .

To learn Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy . This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco.

For additional information on Cisco's vulnerability management, disclosure cadence, and software patching strategy, see Cisco's Transition to a Risk-Based Vulnerability Disclosure Model .

Related to This Advisory

Version Description Section Status Date 1.0 Initial public release. - Final 2026-SEP-16 Show Less

SOFTWARE DOWNLOADS AND TECHNICAL SUPPORT The Cisco Support and Downloads page on Cisco.com provides information licensing and downloads. This page can also display customer device support coverage for customers who use the My Devices tool. Please note that customers may download only software that was procured from Cisco directly or through a Cisco authorized reseller or partner and for which the license is still valid. Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco Technical Assistance Center (TAC) . Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade. When considering software upgrades , customers are advised to regularly consult the advisories for the relevant Cisco products to determine exposure and a complete upgrade solution. In all cases, customers should ensure that the devices to be upgraded contain sufficient memory and confirm that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, customers are advised to the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers. LEGAL DISCLAIMER DETAILS CISCO DOES NOT MAKE ANY EXPRESS OR IMPLIED GUARANTEES OR WARRANTIES OF ANY KIND, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. WITHOUT LIMITING THE GENERALITY OF THE FOREGOING, CISCO DOES NOT GUARANTEE THE ACCURACY OR COMPLETENESS OF THIS INFORMATION. THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME. Copies or summaries of the information contained in this Security Advisory may lack important information or contain factual errors. Customers are advised to visit the Cisco Security Advisories page for the most recent version of this Security Advisory. The Cisco Product Security Incident Response Team (PSIRT) assesses only the affected and fixed release information that is documented in this advisory. See the Cisco Security Vulnerability Policy for more information.

SOFTWARE DOWNLOADS AND TECHNICAL SUPPORT

The Cisco Support and Downloads page on Cisco.com provides information licensing and downloads. This page can also display customer device support coverage for customers who use the My Devices tool. Please note that customers may download only software that was procured from Cisco directly or through a Cisco authorized reseller or partner and for which the license is still valid.

Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco Technical Assistance Center (TAC) . Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade.

When considering software upgrades , customers are advised to regularly consult the advisories for the relevant Cisco products to determine exposure and a complete upgrade solution. In all cases, customers should ensure that the devices to be upgraded contain sufficient memory and confirm that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, customers are advised to the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers.

LEGAL DISCLAIMER DETAILS

CISCO DOES NOT MAKE ANY EXPRESS OR IMPLIED GUARANTEES OR WARRANTIES OF ANY KIND, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. WITHOUT LIMITING THE GENERALITY OF THE FOREGOING, CISCO DOES NOT GUARANTEE THE ACCURACY OR COMPLETENESS OF THIS INFORMATION. THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.

Copies or summaries of the information contained in this Security Advisory may lack important information or contain factual errors. Customers are advised to visit the Cisco Security Advisories page for the most recent version of this Security Advisory. The Cisco Product Security Incident Response Team (PSIRT) assesses only the affected and fixed release information that is documented in this advisory. See the Cisco Security Vulnerability Policy for more information.

Leave additional feedback