Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryperimeter-device-exposureembedded-device-vulnerabilityidentity-authentication-vulnerability

Cisco Secure Firewall flaws expose FMC, FTD, and ASA to RCE, auth bypass, and inspection bypass

Updated 28d agoFirst seen May 25, 20268 sources

Cisco disclosed multiple vulnerabilities affecting Secure Firewall Management Center (FMC), Secure Firewall Threat Defense (FTD), and Adaptive Security Appliance (ASA) software, including a remote code execution flaw tied to RADIUS handling in FMC and a separate authentication bypass issue in on-premises FMC. Additional advisories describe a path traversal vulnerability in FMC and FTD, expanding the risk to core firewall management and security enforcement platforms used in enterprise environments.

The broader set of advisories also includes a Snort deep inspection bypass in FTD, a TLS/Snort 3 denial-of-service issue, a SAML reflected cross-site scripting flaw affecting ASA and FTD, a VPN web services client-side request smuggling vulnerability, and a Lua code injection bug in ASA and FTD. Taken together, the disclosures show that Cisco firewall products were exposed to weaknesses spanning code execution, access control, traffic inspection evasion, denial of service, and web interface exploitation, creating multiple paths for attackers to disrupt defenses or gain elevated access if affected systems remain unpatched.

Share:
Cisco Secure Firewall flaws expose FMC, FTD, and ASA to RCE, auth bypass, and inspection bypass
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
May 3, 20262mo ago

Cisco discloses FMC authentication bypass vulnerability

Cisco published a security advisory for an authentication bypass vulnerability affecting Cisco Secure Firewall Management Center Software.

Apr 3, 20263mo ago

Cisco releases six Secure Firewall advisories

Cisco published a batch of security advisories covering Secure Firewall products, including vulnerabilities for path traversal in FMC and FTD, Snort deep inspection bypass in FTD, SAML reflected XSS in ASA and FTD, VPN web services client-side request smuggling in ASA and FTD, Lua code injection in ASA and FTD, and a TLS/Snort 3 denial-of-service issue in FTD.

Aug 14, 202510mo ago

Cisco discloses FMC RADIUS remote code execution vulnerability

Cisco published a security advisory for a remote code execution vulnerability affecting Cisco Secure Firewall Management Center Software in its RADIUS-related functionality.

SOURCE COVERAGE

Sources

8 references tracked. Mallory keeps watching after this page renders.

8 SOURCESView all
Cisco Security CenterAdvisories
May 3, 2026

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

linkedin.com

Open source
Cisco Product AdvisoriesAdvisories
Apr 3, 2026

Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software Path Traversal Vulnerability

sec.cloudapps.cisco.com

Open source
Cisco Product AdvisoriesAdvisories
Apr 3, 2026

Cisco Secure Firewall Threat Defense Software Snort Deep Inspection Bypass Vulnerability

sec.cloudapps.cisco.com

Open source
Cisco Product AdvisoriesAdvisories
Apr 3, 2026

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SAML Reflected Cross-Site Scripting Vulnerability

sec.cloudapps.cisco.com

Open source
Cisco Product AdvisoriesAdvisories
Apr 3, 2026

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Client-Side Request Smuggling Vulnerability

sec.cloudapps.cisco.com

Open source
Cisco Product AdvisoriesAdvisories
Apr 3, 2026

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability

sec.cloudapps.cisco.com

Open source
Cisco Product AdvisoriesAdvisories
Apr 3, 2026

Cisco Secure Firewall Threat Defense Software TLS with Snort 3 Detection Engine Denial of Service Vulnerability

sec.cloudapps.cisco.com

Open source
Cisco Security CenterAdvisories
Jan 1, 2025

Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability

linkedin.com

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.