CVE-2026-20101

A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload

Severity
High 8.6
CVSS 3.1
Exploited
Not listed
EPSS
0.004
28.0th percentile
Discovered by
Vendor
Published by the vendor
Published
Mar 4, 2026
Assigned by cisco

Description

A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could exploit this vulnerability by sending crafted SAML messages to the SAML service. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Weakness: CWE-330

Affected products

Vendor Product Category Matched by
Cisco Cisco Adaptive Security Appliance (ASA) Firewall / NGFW cna-assigner
Cisco Cisco Secure Firewall Firewall / NGFW cna-assigner
Vendor-reported affected versions (2)
  • Cisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco · Cisco Secure Firewall Threat Defense (FTD) Software