CVE-2026-20103Disclosure(cisco / adaptive_security_appliance_software)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cisco adaptive_security_appliance_software systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition to new Remote Access SSL VPN connections. This does not affect the management interface, though it may become temporarily unresponsive. This vulnerability is due to trusting user input without validation. An attacker could exploit this vulnerability by sending crafted packets to the Remote Access SSL VPN server. A successful exploit could allow the attacker to cause the device web interface to stop responding, resulting in a DoS condition.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • adaptive_security_appliance_software
  • secure_firewall_threat_defense

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-03-04); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
adaptive_security_appliance_softwaresecure_firewall_threat_defense

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-04: 3Mentions · 2026-03-05: 1Mentions · 2026-07-22: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 103-0403-0507-22
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-043
Disclosure3
2026-03-051
Patch1
2026-07-221
General1
Full discourse5 posts
  • Matt Van Bibber@mattvanbibber
    General

    @AzRepGillette @MaricopaVote Last couple months... Check Point: CVE-2026-50751, CVE-2026-50752 Palo Alto: CVE-2026-0283 SonicWall: CVE-2026-15409, CVE-2026-15410 Cisco: CVE-2026-20103 (and related) Microsoft (SSTP): CVE-2026-50694 WireGuard (InHand): CVE-2026-38704

    Post summary

    The tweet merely lists several CVE identifiers, providing no additional details, proofs of exploitation, or remediation guidance.

    0001068
    1.4K followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, profissionais de segurança! Uma vulnerabilidade crítica (CVSS: 8.6) no Remote Access SSL VPN do Cisco ASA/FTD pode causar DoS. 🛡️ Atualize seus sistemas e restrinja o acesso ao serviço. Proteja sua rede! Saiba mais: https://www.tenable.com/cve/CVE-2026-20103 #Cybersecurity #Cisco #VPN

    Post summary

    The tweet warns of a critical DoS vulnerability in Cisco ASA/FTD VPN (CVE‑2026‑20103), provides a Tenable link, and urges users to update systems and limit access.

    0000075
    254 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20103 A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD… https://www.cve.org/CVERecord?id=CVE-2026-20103

    Post summary

    The text announces CVE‑2026‑20103 as a vulnerability in Cisco Secure Firewall’s Remote Access SSL VPN functionality, but it offers no proof‑of‑concept, exploit details, or patch information.

    00000123
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-20103: HIGH] Critical vulnerability in Cisco Secure Firewall ASA and FTD software allows remote attackers to exploit SSL VPN, causing denial of service by depleting memory.#cve,CVE-2026-20103,#cybersecurity https://cvefind.com/CVE-2026-20103

    Post summary

    The post announces a high‑severity denial‑of‑service vulnerability in Cisco Secure Firewall ASA and FTD that allows remote attackers to exploit the SSL VPN and exhaust system memory.

    0000050
    595 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-20103 - High A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an... https://www.thehackerwire.com/vulnerability/CVE-2026-20103/ https://t.co/716HrhU5IK

    Post summary

    The post announces CVE-2026-20103 affecting Cisco Secure Firewall and points to a news article covering it.

    0000042
    121 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoadaptive_security_appliance_software---
Appciscosecure_firewall_threat_defense---

Explore more