CVE-2026-20012
A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure
Description
A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper parsing of IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit of Cisco IOS Software and IOS XE Software could allow the attacker to cause the affected device to reload, resulting in a DoS condition. A successful exploit of Cisco Secure Firewall ASA Software and Secure FTD Software could allow the attacker to partially exhaust system memory, resulting in system instability, such as the inability to establish new IKEv2 VPN sessions. A manual reboot of the device is required to recover from this condition.
Weakness: CWE-401
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Adaptive Security Appliance (ASA) Check your version | Firewall / NGFW | cna-assigner |
| Cisco | Cisco Firepower Threat Defense (FTD) Check your version | Firewall / NGFW | cna-assigner |
| Cisco | Cisco IOS Software | Routing & Switching | cna-assigner |
| Cisco | Cisco IOS XE Software | Routing & Switching | cna-assigner |
Vendor-reported products (4)
- Cisco · IOS
- Cisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco · Cisco IOS XE Software
- Cisco · Cisco Secure Firewall Threat Defense (FTD) Software
Vendor advisory
cisco-sa-asa-ftd-ios-dos-kPEpQGGK
Cisco IOS, IOS XE, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability
Cisco’s rating: High (advisory CVSS 8.6) · Published Mar 25, 2026
Bug IDs: CSCwq01495 , CSCwq01523
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from