Security Advisory Desk
highQCS priority 100/100Cisco

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

A security weakness in Cisco Secure Firewall ASA and Threat Defense software allows an unauthenticated remote attacker to overload the device's memory by sending many new SSL/TLS connection attempts. This causes the device to slow down and stop processing SSL VPN connections, leading to denial of service. There are no workarounds, but Cisco has released software updates to fix the issue.

Published 16/9/2026, 4:05:50 pmVerified 16/9/2026, 7:45:46 pmRevision 1
Cisco high network security advisory visual

In plain language

What this advisory means

A security weakness in Cisco Secure Firewall ASA and Threat Defense software allows an unauthenticated remote attacker to overload the device's memory by sending many new SSL/TLS connection attempts. This causes the device to slow down and stop processing SSL VPN connections, leading to denial of service. There are no workarounds, but Cisco has released software updates to fix the issue.

Technical explanation

How the issue affects the environment

The vulnerability arises from improper memory management of new incoming SSL/TLS connections in the VPN and management web servers of Cisco Secure Firewall ASA and Threat Defense platforms. An unauthenticated attacker can exploit this by sending a large volume of SSL/TLS handshake requests, causing the device to deplete system memory or buffer blocks. This depletion results in a denial of service as SSL VPN connections slow and eventually stop. Recovery of memory or buffers is slow once attack traffic stops; a manual reload of the device may be needed for rapid restoration. Cisco has released fixed software versions that address this memory handling flaw. No mitigations or workarounds are documented.

Operational impact

Why teams should care

This vulnerability can cause Cisco Secure Firewall ASA and Threat Defense devices to experience degraded or halted SSL VPN services due to memory exhaustion, potentially disrupting remote access and management functions. This denial of service can impact business operations relying on secure VPN connectivity. Rapid recovery may require manual device reloads, leading to operational downtime and resource expenditure.

Immediate action

Cisco strongly recommends upgrading to the software releases provided as fixed versions for this vulnerability. Users should consult Cisco's Security Advisory and Software Checker tools to identify the appropriate fixed releases and perform an update to remediate the issue. No workarounds are available, and manual device reloads may be necessary for rapid recovery following exploitation.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

There are no workarounds available for this vulnerability as per Cisco's advisory.

Evidence and validation checklist

  • Cisco official Security Advisory page for the vulnerability
  • Description of the memory exhaustion vulnerability due to SSL/TLS connection handling
  • Cisco statement that no workarounds exist
  • Cisco recommendation to upgrade to fixed software releases
  • CVE identifier CVE-2024-20260
  • Lack of public exploitation evidence from Cisco PSIRT

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source