This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco cisco:adaptive Security Appliance Software Cisco secure Firewall Threat Defense |
|
| Vendors & Products |
Cisco
Cisco cisco:adaptive Security Appliance Software Cisco secure Firewall Threat Defense |
Thu, 17 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks. | |
| Title | CIsco FTD Bypass Access List | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-09-18T19:08:46.060Z
Reserved: 2025-10-08T11:59:15.377Z
Link: CVE-2026-20121
Updated: 2026-09-17T15:56:42.947Z
Status : Awaiting Analysis
Published: 2026-09-16T21:17:07.467
Modified: 2026-09-18T13:28:28.567
Link: CVE-2026-20121
No data.
OpenCVE Enrichment
Updated: 2026-09-18T20:38:04Z