CVE-2026-20249: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability

Published Sep 16, 2026
·
Updated

A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attempting to establish an IKEv2 VPN connection with a crafted certificate. A successful exploit could allow the attacker to cause the IKEv2 process to crash, causing a denial of service (DoS) condition.

Affected Software

2 affected components
Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Cisco Cisco Secure Firewall Threat Defense (FTD) Software

Event History

Sep 16, 2026
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Cisco Secure Firewall ASA Software and Cisco Secure Firewall FTD Software deployments are affected when they use IKEv2 certificate authentication. The issue occurs during the certificate-authentication phase of IKEv2 connection setup.

2

Does an attacker need credentials or user interaction to trigger the denial of service?

No. An unauthenticated remote attacker can attempt to establish an IKEv2 VPN connection using a crafted certificate; no user interaction is required.

3

What is the operational impact of successful exploitation?

Successful exploitation can crash the IKEv2 process and cause the affected device to reload unexpectedly, resulting in a denial-of-service condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203