Security Advisory Desk
highQCS priority 100/100Cisco

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability

Cisco Secure Firewall devices that use the IKEv2 VPN feature with certificate authentication can be crashed remotely by unauthenticated attackers. This means attackers can cause the firewall to restart or stop responding, denying legitimate users access to network resources. There are no temporary fixes, so users must update to the latest Cisco software version to resolve the problem.

Published 18/9/2026, 3:50:30 pmVerified 19/9/2026, 1:11:00 amRevision 1
Cisco high network security advisory visual

In plain language

What this advisory means

Cisco Secure Firewall devices that use the IKEv2 VPN feature with certificate authentication can be crashed remotely by unauthenticated attackers. This means attackers can cause the firewall to restart or stop responding, denying legitimate users access to network resources. There are no temporary fixes, so users must update to the latest Cisco software version to resolve the problem.

Technical explanation

How the issue affects the environment

A logic error in the certificate authentication phase during IKEv2 VPN connection setup on Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software allows unauthenticated remote attackers to craft a certificate that triggers a crash in the IKEv2 process. This crash leads to a denial of service (DoS) by forcing the device to reload or become unresponsive. The flaw exists when IKEv2 with certificate authentication is enabled, and exploitation involves initiating a VPN connection using a malformed certificate. Cisco has released software updates that fix this vulnerability by correcting the authentication logic.

Operational impact

Why teams should care

A successful attack causes the VPN server on Cisco Secure Firewall devices to crash, leading to downtime. This disrupts secure remote access, potentially halting business operations relying on VPN connectivity. The denial of service could impact many users simultaneously, degrading network security posture and availability until the device is patched or rebooted.

Immediate action

Administrators should upgrade affected Cisco Secure Firewall ASA and FTD devices to the fixed software releases provided by Cisco that correct the certificate authentication logic error in IKEv2. This upgrade eliminates the vulnerability and prevents denial of service attacks exploiting this flaw.

Affected and fixed releases

Affected versionsCisco Secure Firewall ASA Software releases up to 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47, 9.24.1.26 and earlier as specified by Cisco, Cisco Secure FTD Software releases up to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 as specified by Cisco
Fixed versionsCisco Secure Firewall ASA Software 9.16.4.103 and later incremental fixed releases, Cisco Secure Firewall FTD Software 7.0.10 and later incremental fixed releases

Temporary risk reduction

Cisco has stated that there are no available workarounds for this vulnerability. Customers must apply the fixed software releases to mitigate the issue.

Evidence and validation checklist

  • Cisco official advisory confirming vulnerability details and fixes
  • Description of logic error in IKEv2 certificate authentication
  • No workarounds available
  • Fixed software releases published by Cisco
  • Exploit scenario involving crafted certificate triggering crash
  • No public proof of exploitation reported

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
Cisco Secure Firewall Adaptive Security | Advisory | QCS