CVE-2026-20014
7.7Cisco · Secure Firewall (ASA and FTD Software)
A memory leak in the IKEv2 packet processing feature of Cisco Secure Firewall ASA and FTD software allows authenticated remote attackers to cause a denial of service via memory exhaustion.
Executive summary
An authenticated remote attacker can trigger a denial of service on Cisco Secure Firewall devices by sending crafted IKEv2 packets, potentially causing the device to reload and impacting network availability.
Vulnerability
This vulnerability (CWE-401) is caused by the improper processing of IKEv2 packets, which leads to memory exhaustion. An attacker must possess valid VPN user credentials to successfully send the crafted packets required to trigger the crash.
Business impact
A successful exploit results in a denial of service, forcing the firewall to reload and disrupting all traffic passing through the device. Given the CVSS score of 7.7, this represents a high risk to business continuity, particularly for remote workforce connectivity and inter-site communications, as the interruption can extend beyond the local device to impact wider network availability.
Remediation
Immediate Action: Update affected Cisco Secure Firewall ASA and FTD software to the latest patched versions as provided in the vendor security advisory.
Proactive Monitoring: Monitor firewall system logs for recurring IKEv2 errors or unexpected device reloads that may indicate an exploitation attempt.
Compensating Controls: While no direct workaround is provided, organizations should restrict VPN access to known, trusted IP ranges to reduce the likelihood of credential-based exploitation.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Although this vulnerability requires authenticated access, the potential for total service disruption makes it a high-priority item for network security teams. Administrators should prioritize the installation of the vendor-supplied patches to ensure the stability and availability of perimeter and VPN security infrastructure.