Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2026-20121
Cisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

CIsco FTD Bypass Access List

Description

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.

Affected Products

VendorProductVersions
CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) Software9.23.1, 9.22.1.1, 9.22.1.3, 9.22.1.2, 9.22.1.6, 9.22.2, 9.23.1.3, 9.22.2.4, 9.23.1.7, 9.22.2.9, 9.23.1.13, 9.22.2.13, 9.23.1.19, 9.22.2.14, 9.23.1.22, 9.22.2.20, 7.6.0, 7.7.0, 7.6.1, 7.6.2, 7.7.10, 7.7.11, 7.6.2.1, 7.7.10.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco secure firewall threat defense (ftd) softwaremitre_affected90%
ciscisco asa (adaptive security appliance)cert_advisory90%
ciscisco secure firewall threat defensecert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-acl-bypass-8p6vFvw

Related News (2 articles)

Tier B
BSI Advisories10d ago
[NEU] [hoch] Cisco Secure FTD und ASA: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB11d ago
CVE-2026-20121 | Cisco Secure Firewall Adaptive Security Appliance Software Object Group Search access control
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
CWECWE-284
PublishedSep 16, 2026
Last enriched11d ago
Trending Score13
Source articles2
Independent2
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-76447
Cisco Identity Services Engine Certificate Reload Vulnerability
Trending: 13
MEDIUMCVE-2026-76427
Cisco ISE XML External Entity Injection Vulnerability
Trending: 11
MEDIUMCVE-2026-76426
Cisco ISE REST API SQL Injection Vulnerability
Trending: 11
MEDIUMCVE-2026-76431
Cisco Identity Services Engine Arbitrary File Deletion Vulnerability
Trending: 10
HIGHCVE-2026-20293
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 16, 2026
Discovered by ZDM
Sep 16, 2026