Redpacketsecurity Cisco ASA Software Vulnerabilities CVE-2026-20335 and CVE-2026-20336 Disclosed
Article Content
- •Two high-risk vulnerabilities in Cisco ASA Software disclosed: CVE-2026-20335 and CVE-2026-20336.
- •Both vulnerabilities allow potential disruption of traffic and alteration of security policies.
- •Organizations with exposed management interfaces are at highest risk; prompt remediation is essential.
Cisco has disclosed two high-risk vulnerabilities in its Secure Adaptive Security Appliance Software, tracked as CVE-2026-20335 and CVE-2026-20336, both published on 2026-09-16. CVE-2026-20336 involves improper resource control, while CVE-2026-20335 relates to incorrect calculations. Both vulnerabilities could allow attackers to disrupt traffic, alter security policies, or gain access to sensitive management functions. Organizations with internet-facing firewalls or shared administration networks are particularly vulnerable. Current evidence shows no known exploitation of these vulnerabilities, but they require prompt remediation. Cisco recommends applying the fixed software release and restricting management access to mitigate risks. Monitoring for unusual activity on affected devices is also advised.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cisco and CVE-2026-20335 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…