Cisco has published a batch of security advisories for its firewall products, and four of the flaws they close carry critical scores of 9.6 to 9.9 out of 10 in the US National Vulnerability Database. The affected software is the firewall itself and the console administrators use to run it: Cisco Secure Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, and Cisco Secure Firewall Management Center (FMC) Software.
Hong Kong's HKCERT relayed the batch in a security bulletin published on 17 September, where the whole set is rated medium risk. The NVD entries for four of the identifiers say otherwise.
Cisco found these itself
Cisco's own wording, carried into the NVD records, is that its ASA, FTD and FMC engineering team conducted a comprehensive internal security review and shipped a software hardening release covering multiple internally discovered vulnerabilities. That is worth reading in both directions. Nobody is reporting these as exploited and no outside researcher is credited, because the finder was Cisco. It also means one upgrade closes a block of issues rather than a single bug.
It is the second hardening release of this kind IntelFusions has covered in a fortnight. The IOS XR equivalent ran here on 3 September, and seven of the 22 CVE identifiers in the HKCERT bulletin, CVE-2026-20274 through CVE-2026-20280, are that earlier IOS XR set rather than anything new.
The four that are scored critical
The NVD records group each critical identifier under a broad weakness family rather than describing an exploit path. CVE-2026-20329 (9.9) is filed under improper handling of exceptional conditions. CVE-2026-20330 (9.9) covers improper neutralization. CVE-2026-20332 (9.9) covers improper access control. CVE-2026-20331 (9.6) covers a failure of a protection mechanism. Cisco has published no exploitation detail for any of them, and neither the NVD records nor the HKCERT bulletin describe how an attacker would reach them, so the score is the only severity signal available today.
The rest of the batch is filed as separate Cisco advisories covering denial of service conditions in IKEv2 certificate handling, EIGRP, DTLS, logging and TCP DNS processing, plus an access control list bypass in Threat Defense. HKCERT lists the combined impact of the whole set as denial of service and security restriction bypass.
Upgrade the platform, not one advisory at a time
Neither the bulletin nor the NVD entries carry fixed version numbers. Those live in Cisco's own hardening advisory and the seven advisories published alongside it, and because a hardening release bundles many fixes into one train, the practical move is to take the recommended release for your platform rather than chase individual CVE numbers. Management centers deserve to go first: FMC has been in attackers' hands before, and IntelFusions covered state crews and ransomware affiliates rooting FMC servers earlier this month.
Cisco's internal reviews keep producing bundles like this one, which says something good about the reviews and something uncomfortable about the install base. A hardening release only hardens the deployments that take it.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.