Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitywidely-deployed-product-advisoryperimeter-device-exposureembedded-device-vulnerability

Actively Exploited Critical Vulnerabilities in Cisco Secure Firewall and Catalyst SD-WAN Manager

Updated 3mo agoFirst seen Mar 6, 20262 sources

Belgium’s CCB (Safeonweb) warned of multiple critical vulnerabilities across several Cisco products—specifically calling out Cisco Secure Firewall (including Adaptive Security Appliance (ASA), Firepower Management Center (FMC), and Firepower Threat Defense (FTD)) and Cisco Catalyst SD-WAN Manager—and stated that some vulnerabilities are being actively exploited, urging immediate patching. The advisory lists a broad set of weakness classes including authentication bypass (CWE-288/CWE-287), deserialization of untrusted data (CWE-502), buffer overflow (CWE-120), SQL injection (CWE-89), and sensitive information exposure (CWE-200), and highlights multiple CVEs including CVE-2026-20079 and CVE-2026-20131 with CVSS 10.0.

A separate advisory from the Center for Internet Security (CIS) also reported multiple vulnerabilities in Cisco products that could enable remote code execution, enumerating a large set of related CVEs (including CVE-2026-20001, CVE-2026-20002, CVE-2026-20003, and CVE-2026-20039). Taken together, the advisories indicate a high-risk patching priority for organizations running affected Cisco network/security management and firewall platforms, particularly where internet exposure or untrusted management-plane access could make exploitation more likely.

Share:
Actively Exploited Critical Vulnerabilities in Cisco Secure Firewall and Catalyst SD-WAN Manager
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Mar 5, 20264mo ago

Authorities and security organizations warn that some Cisco flaws are actively exploited

On the same day, Belgium's CCB Safeonweb warned about multiple critical Cisco vulnerabilities and urged immediate patching, noting that some were being actively exploited. CIS also issued an advisory aggregating the affected CVEs and Cisco security notices for defenders.

Cisco discloses multiple critical vulnerabilities across several products

Cisco published a set of security advisories covering multiple vulnerabilities in products including Cisco Secure Firewall and Cisco Catalyst SD-WAN Manager. The advisories referenced issues such as remote code execution, authentication bypass, SQL injection, command injection, directory traversal, cross-site scripting, and denial-of-service flaws.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

55 LINKEDOpen in app
Vulnerabilities
53 linked
Authenticated SQL injection in Cisco Secure Firewall Management Center (FMC) REST APIAuthenticated SQL injection in Cisco Secure FMC web-based management interfaceAuthenticated SQL injection in Cisco Secure FMC REST APIUnauthenticated Root RCE in Cisco Secure Firewall Management Center Web InterfaceDoS via crafted HTTP to Remote Access SSL VPN Lua interpreter in Cisco ASA/FTDAuthentication Bypass to Root RCE in Cisco Secure Firewall Management CenterUnauthenticated Remote DoS via memory exhaustion in Cisco ASA/FTD Remote Access SSL VPNCisco Secure Firewall ASA/FTD SAML SSO DoSCisco Secure Firewall ASA/FTD Remote Access SSL VPN Memory Exhaustion DoSCisco Secure Firewall ASA and FTD Remote Access SSL VPN Authenticated Memory Exhaustion DoSCisco Secure Firewall ASA TCP Flood Denial of Service VulnerabilityCisco Secure Firewall ASA/FTD VPN Web Server Denial of Service VulnerabilityCisco Secure Firewall ASA multiple context mode SCP cross-context file accessArbitrary File Overwrite in Cisco Catalyst SD-WAN Manager APIInformation Disclosure in Cisco Catalyst SD-WAN Manager DCACisco Catalyst SD-WAN Manager REST API Privilege EscalationInformation Disclosure in Cisco Catalyst SD-WAN Manager vshellCisco Catalyst SD-WAN Manager API Authentication BypassDoS via OSPF packet parsing in Cisco Secure Firewall ASA/FTDDoS in Snort 3 Detection Engine via crafted VBA decompression dataDoS via OSPF packet parsing memory corruption in Cisco Secure Firewall ASA/FTDDoS via crafted RPC parsing in Snort 3 detection engine (Cisco products)DoS via IKEv2 packet parsing memory leak in Cisco Secure Firewall ASA/FTDDoS via crafted OSPF LSU packets in Cisco Secure Firewall ASA/FTD (heap corruption)DoS via OSPF LSU out-of-bounds write in Cisco Secure Firewall ASA/FTD (OSPF canonicalization debug)DoS via Snort 3 Detection Engine binder module initialization logic (Cisco products)DoS in Snort 3 VBA decompression error handling (infinite loop)Cisco Secure Firewall ASA/FTD IKEv2 Memory Exhaustion DoSDoS via heap overflow in Snort 3 VBA decompression (Cisco products)DoS in Cisco Snort 3 Detection Engine via crafted HTTP mDNS header parsingAuthenticated CLI command injection in Cisco Secure FTD (root OS command execution)Authenticated CLI input validation DoS in Cisco Secure Firewall Threat Defense (FTD)Cisco Secure Firewall ASA and Secure FTD IKEv2 Denial of Service VulnerabilityDoS in Cisco Snort 3 Detection Engine via crafted SSL handshake parsingDoS in Snort 3 Detection Engine via JSTokenizer HTTP JavaScript normalizationAuthenticated CLI command injection in Cisco Secure FTD Software (root OS command execution)OSPF update packet processing buffer overflow DoS in Cisco Secure Firewall ASA/FTDOSPF heap corruption DoS in Cisco Secure Firewall ASA/FTDAuthenticated command injection in Cisco FXOS CLI for Cisco Secure Firewall ASA/FTDAuthenticated command injection in Cisco Secure Firewall Management Center (FMC) lockdown remediation modulesDoS in Cisco Snort 3 VBA decompression error handlingXSS in Cisco Secure Firewall ASA/FTD VPN web servicesArbitrary file write as root via path traversal in Cisco Secure Firewall FMC/FTD sftunnel file synchronizationLua code injection leading to root RCE in Cisco Secure Firewall ASA/FTD CLI commandsACL bypass in Cisco Secure Firewall ASA/FTD clustering rule replicationSnort deep packet inspection rule bypass in Cisco Secure Firewall Threat Defense (FTD)Cisco Secure Firewall ASA/FTD IKEv2 IPsec GCM Traffic Denial of ServiceDoS via crafted TLS packet in Snort 3 Detection Engine (Cisco Secure Firewall FTD)DoS via Snort 3 SSL packet inspection memory management logic error in Cisco Secure Firewall FTDDoS in Cisco Secure Firewall FTD SSL Decryption Do Not Decrypt exclusion (TLS 1.2)SSH key-based authentication bypass in Cisco Secure Firewall ASA proprietary SSH stackClient-side request smuggling in Cisco Secure Firewall ASA/FTD VPN web servicesReflected XSS in Cisco Secure Firewall ASA/FTD SAML 2.0 SSO
Organizations
2 linked
Cisco SystemsHelp Net Security
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Actively Exploited Critical Vulnerabilities in Cisco Secure Firewall and Catalyst SD-WAN Manager | Mallory