In plain language
What this advisory means
Two security weaknesses were found in Cisco Secure Firewall devices that could let remote attackers sneak past access controls without logging in. This happens because of a logic error in how the firewall handles group-based access rules. Attackers could send disallowed traffic through the firewall, reaching protected parts of the network. Cisco has issued software updates to fix these problems. There are no workarounds to safely avoid these flaws except upgrading to the fixed releases.
Technical explanation
How the issue affects the environment
The vulnerabilities exist in the Access Control List (ACL) Object Group Search (OGS) implementation within Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. Due to a logic error when populating group access control policies (ACPs) configured with OGS, certain traffic that should be blocked can bypass ACL enforcement. This flaw allows unauthenticated, remote attackers to send traffic through the firewall that circumvents configured ACL restrictions, potentially reaching protected network resources. Cisco identified this issue through TAC support case analysis and has provided fixed software releases to address these ACL bypass vulnerabilities (CVE-2026-20120, CVE-2026-20121). No mitigations or workarounds exist other than applying these software updates.
Operational impact
Why teams should care
Successful exploitation could allow attackers to bypass firewall access controls and access sensitive or critical network assets that should be protected. This exposure threatens the confidentiality and integrity of protected systems, posing risks depending on the value of the resources behind the firewall. Organizations using vulnerable Cisco Secure Firewall ASA or FTD software with ACLs configured using Object Group Search should prioritize upgrading to fixed software to maintain network security.
Immediate action
To remediate these vulnerabilities, customers must upgrade their Cisco Secure Firewall ASA and FTD devices to the fixed software versions listed in this advisory. Cisco strongly recommends applying these updates promptly, as no workarounds are available to mitigate the issue. Upgrade procedures should be followed according to Cisco's published guides and best practices to ensure proper deployment and continued device functionality.
Affected and fixed releases
Temporary risk reduction
There are no workarounds or temporary mitigations available for these vulnerabilities. Applying the fixed software versions provided by Cisco is required to eliminate the risk of ACL bypass.
Evidence and validation checklist
- Cisco security advisory publication dated September 16, 2026, confirms vulnerabilities and affected products.
- Cisco provides lists of vulnerable and fixed software versions with explicit recommendations to upgrade.
- No workaround or mitigation is offered besides upgrades.
- Vulnerabilities found during Cisco TAC support case investigation.
- Exploit scenario involves bypassing ACLs configured with Object Group Search.
- Official CVE identifiers CVE-2026-20120 and CVE-2026-20121 assigned and documented.
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
