CVE-2026-20050
Last modified
CVE-2026-20050 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. A vulnerability in the Do Not Decrypt exclusion feature of the SSL decryption feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management during the inspection of TLS 1.2 encrypted traffic. An attacker could exploit this vulnerability by sending crafted TLS 1.2 encrypted traffic through an affected device. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
A vulnerability in the Do Not Decrypt exclusion feature of the SSL decryption feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management during the inspection of TLS 1.2 encrypted traffic. An attacker could exploit this vulnerability by sending crafted TLS 1.2 encrypted traffic through an affected device. A successful exploit could allow the attacker to cause a reload of an affected device. Note: This vulnerability only affects traffic that is encrypted by TLS 1.2. Other versions of TLS are not affected.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Secure Firewall Threat Defense | >= 7.1.0, < 7.2.11 |
| Cisco | Secure Firewall Threat Defense | >= 7.3.0, < 7.4.4 |
| Cisco | Secure Firewall Threat Defense | >= 7.6.0, < 7.6.4 |
| Cisco | Secure Firewall Threat Defense | >= 7.7.0, < 7.7.11 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-20050?
How severe is CVE-2026-20050?
How do I fix CVE-2026-20050?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-20045A vulnerability in Cisco Unified Communications Manager (Uni…9.8
- CVE-2026-20046A vulnerability in task group assignment for a specific CLI …8.8
- CVE-2026-20047A vulnerability in the web-based management interface of Cis…4.8
- CVE-2026-20048A vulnerability in the Simple Network Management Protocol (S…7.7
- CVE-2026-20049A vulnerability in the processing of Galois/Counter Mode (GC…7.7
- CVE-2026-2005Heap buffer overflow in PostgreSQL pgcrypto allows a ciphert…8.8
- CVE-2026-20051A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress…7.4
- CVE-2026-20052A vulnerability in the memory management handling for the Sn…5.8
- CVE-2026-20053Multiple Cisco products are affected by a vulnerability in t…5.8
- CVE-2026-20054Multiple Cisco products are affected by a vulnerability in t…5.8
- CVE-2026-20055Multiple vulnerabilities in the web-based management interfa…4.8
- CVE-2026-20056A vulnerability in the Dynamic Vectoring and Streaming (DVS)…4
Are you affected by CVE-2026-20050?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
