CVE-2026-20069Disclosure(cisco / adaptive_security_appliance_software)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device. This vulnerability is due to improper validation of HTTP requests. An attacker could exploit this vulnerability by persuading a user to visit a website that is designed to pass malicious HTTP requests to a device that is running Cisco Secure Firewall ASA Software or Cisco Secure FTD Software and has web services endpoints supporting VPN features enabled. A successful exploit could allow the attacker to reflect malicious input from the affected device to the browser that is in use and conduct browser-based attacks, including cross-site scripting (XSS) attacks. The attacker is not able to directly impact the affected device.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • adaptive_security_appliance_software
  • secure_firewall_threat_defense

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
adaptive_security_appliance_softwaresecure_firewall_threat_defense

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-04: 2Technical Details · 2026-03-04: 103-04
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20069 Cisco Secure Firewall ASA and FTD VPN Web Services Reflected XSS ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20069 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces the CVE with basic technical detail (a reflected XSS) and links to a vulnerability details page, without providing PoC, exploit, or patch information.

    0000071
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-20069 A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) S… https://www.cve.org/CVERecord?id=CVE-2026-20069

    Post summary

    The post merely references CVE-2026-20069 with a link to its CVE record, offering no further detail on exploitation, patches, or technical specifics.

    00000100
    56.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoadaptive_security_appliance_software---
Appciscosecure_firewall_threat_defense---

Explore more