Security Advisory Desk
mediumQCS priority 82/100Cisco

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability

A weakness in Cisco Secure Firewall ASA and Threat Defense software's handling of DNS over TCP allows attackers to crash the device by sending specially crafted DNS responses. This can cause the firewall to reload, leading to downtime and service interruptions. Attackers must be able to intercept or control DNS responses to exploit this. Cisco has released software updates to fix this issue, but no temporary workarounds exist.

Published 18/9/2026, 3:50:29 pmVerified 19/9/2026, 5:51:26 amRevision 1
Cisco medium network security advisory visual

In plain language

What this advisory means

A weakness in Cisco Secure Firewall ASA and Threat Defense software's handling of DNS over TCP allows attackers to crash the device by sending specially crafted DNS responses. This can cause the firewall to reload, leading to downtime and service interruptions. Attackers must be able to intercept or control DNS responses to exploit this. Cisco has released software updates to fix this issue, but no temporary workarounds exist.

Technical explanation

How the issue affects the environment

Cisco Secure Firewall ASA and Threat Defense software contain a logic error in their DNS over TCP implementation. When parsing DNS queries and tracking buffer sizes, a vulnerability allows crafted DNS replies to cause the TCP DNS response handler to unexpectedly restart. This restart causes the entire device to reload, resulting in a denial-of-service condition. Exploitation requires the attacker to respond to the target's DNS queries, either by controlling the DNS server or performing a man-in-the-middle attack. Cisco has addressed this issue in specific software releases; however, no effective workarounds are available.

Operational impact

Why teams should care

Successful exploitation causes the firewall device to reload, leading to service outages and potential loss of availability. This denial-of-service condition impacts network security operations by interrupting firewall protections and connectivity, potentially exposing enterprise networks to further risk.

Immediate action

Upgrade affected Cisco Secure Firewall ASA and Secure FTD software installations to the fixed releases listed in the advisory to remediate the vulnerability. Cisco strongly recommends applying these updates promptly to prevent exploitation.

Affected and fixed releases

Affected versionsCisco Secure Firewall ASA Software versions 9.16 and earlier; other specific versions as detailed in Cisco advisory
Fixed versionsCisco Secure Firewall ASA Software 9.16.4.103 and later fixed releases; Secure FTD Software 7.0.10 and later fixed releases as per Cisco advisory

Temporary risk reduction

Cisco states there are no workarounds available that address this vulnerability. Customers must apply software updates to remediate the issue.

Evidence and validation checklist

  • Cisco official advisory confirming vulnerability and details
  • Detailed vulnerability description and exploitation requirements
  • List of affected and fixed software versions
  • Statement of no available workarounds
  • Acknowledgment of no known public exploitation
  • Cisco recommendation to upgrade software

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source