CVE-2026-20121: CIsco FTD Bypass Access List
A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Cisco Secure Firewall ASA Software and Cisco Secure Firewall FTD Software deployments are affected when group access control policies are configured with ACL Object Group Search (OGS).
What does an attacker need to exploit it?
An attacker can exploit the issue remotely without authentication by sending traffic that should have been blocked by the device's configured access controls.
What is the impact of successful exploitation?
Traffic may bypass configured access controls, allowing the attacker to reach devices located in protected networks.