CISCO fixed 18 vulnerabilities in its Secure Firewall product range on 16 September 2026, covering Firewall Management Center (FMC), Adaptive Security Appliance (ASA) and Threat Defense software. The group comprises eight critical and 10 high-severity flaws, with CVSSv3 scores reaching 9.9. Several could allow remote code execution with root privileges.
The most serious include CVE-2026-20242, a CVSS 9.8 Java deserialisation vulnerability that Cisco says could let an unauthenticated attacker send a crafted Java byte stream and execute arbitrary commands as root, and CVE-2026-20324, a CVSS 9.9 sftunnel flaw that can also lead to root access. CVE-2026-20329, CVE-2026-20330 and CVE-2026-20332 each have a 9.9 score and affect ASA, Threat Defense and FMC software.
Other issues include CVE-2026-20344, an SQL injection vulnerability rated 8.8, as well as flaws involving privilege escalation and information disclosure. Cisco’s advisories provide the affected versions and fixed builds. The company’s PSIRT team said it was not aware of public announcements or malicious use of the vulnerabilities, and no confirmed proof-of-concept was reported.
Organisations using the affected products should upgrade to Cisco’s fixed releases without delay. The article says most flaws have no workaround, and recommends prioritising the unauthenticated root-level vulnerabilities before applying the remaining FMC, ASA and Threat Defense updates. Management access should also be restricted to trusted hosts.