Unauthenticated RCE in Secure Firewall Management Center

Cisco released updates for Secure Firewall ASA and FTD to fix six OSPF protocol denial-of-service vulnerabilities. The flaws (CVE-2026-20020 through CVE-2026-20025) can trigger OSPF adjacency failures, device reloads, or loss of availability.

Part of the PlainSec briefing for 2026-03-27

Sources