Skip to content
Cisco ASA Software Vulnerabilities CVE-2026-20335 and CVE-2026-20336 Disclosed

Cisco ASA Software Vulnerabilities CVE-2026-20335 and CVE-2026-20336 Disclosed

First seen 17 Sep 2026, 16:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 18:24 UTC
  • Two high-risk vulnerabilities in Cisco ASA Software disclosed: CVE-2026-20335 and CVE-2026-20336.
  • Both vulnerabilities allow potential disruption of traffic and alteration of security policies.
  • Organizations with exposed management interfaces are at highest risk; prompt remediation is essential.

Cisco has disclosed two high-risk vulnerabilities in its Secure Adaptive Security Appliance Software, tracked as CVE-2026-20335 and CVE-2026-20336, both published on 2026-09-16. CVE-2026-20336 involves improper resource control, while CVE-2026-20335 relates to incorrect calculations. Both vulnerabilities could allow attackers to disrupt traffic, alter security policies, or gain access to sensitive management functions. Organizations with internet-facing firewalls or shared administration networks are particularly vulnerable. Current evidence shows no known exploitation of these vulnerabilities, but they require prompt remediation. Cisco recommends applying the fixed software release and restricting management access to mitigate risks. Monitoring for unusual activity on affected devices is also advised.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-20336 published
Cisco disclosed CVE-2026-20336, involving improper control of resources in ASA Software.
Redpacketsecurity
2026-09-16
CVE-2026-20335 published
Cisco disclosed CVE-2026-20335, related to incorrect calculations in ASA Software.
Redpacketsecurity
2026-09-17
Cisco issues remediation guidance
Cisco recommends applying fixed software releases and restricting management access to mitigate risks.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track Cisco and CVE-2026-20335 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed