CVE-2026-20290: Cisco Secure Firewall Threat Defense FTD Software

Medium severity, CVSS 5.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart. This vulnerability is due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2. A successful exploit could allow the attacker to cause the Snort 2 Detection Engine to restart unexpectedly, resulting in a denial of service (DoS) condition.

Affected products

  • Cisco Cisco Secure Firewall Threat Defense FTD Software: version 7.0.0 only; version 7.0.0.1 only; version 7.0.1 only; version 7.0.1.1 only; version 7.0.2 only; version 7.2.0 only; …

Published 2026-09-16. Last modified 2026-09-18.