rootpwn

Advisories

Critical Cisco Hardening Release: ASA, FTD, FMC Patch Internal Exploits

Cisco’s security team has rolled out a hardening update for its Secure Firewall Adaptive Security Appliance, Threat Defense, and Management Center software, addressing a suite of internally discovered flaws. Eight CVEs (CVE‑2026‑20329 through CVE‑2026‑20336) cover issues ranging from static credential exposure to authentication bypass, with two vulnerabilities already being actively exploited. No workarounds exist; customers must install the patches promptly to mitigate the critical risk.

Cisco’s internal security audit uncovered a cluster of weaknesses across its flagship firewall products. The findings, now bundled into a single hardening release, span the Adaptive Security Appliance (ASA), Threat Defense (FTD), and Management Center (FMC).

Eight CVE identifiers (CVE‑2026‑20329 to CVE‑2026‑20336) represent distinct Common Weakness Enumeration (CWE) classes. Two of these flaws are confirmed to be in the wild, enabling attackers to hijack credentials or bypass authentication controls.

Key Impact Areas

  • Static credential leakage in FMC
  • Authentication bypass across ASA and FTD
  • Other critical code‑path vulnerabilities affecting configuration and management modules

Cisco has issued no interim workarounds; the only viable defense is to apply the latest firmware updates. The release carries a Critical severity rating, underscoring the urgency for all customers to act immediately.

"This hardening update is part of our commitment to proactive security and product quality," the Cisco engineering team said.

Cisco ASA FTD FMC CVE Hardening Critical Vulnerabilities

← All news