CVE-2026-20064: Cisco Secure Firewall Threat Defense

Medium severity, CVSS 6.5. EPSS: 0.1% chance of exploitation in the next 30 days.

A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the CLI prompt. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Affected products

  • Cisco Secure Firewall Threat Defense: version 6.2.3 only; version 6.4.0 only; version 6.4.0.1 only; version 6.4.0.2 only; version 6.4.0.3 only; version 6.4.0.4 only; …

Published 2026-03-04. Last modified 2026-08-11.