Secure Firewall ASA and FTD
CVE-2026-20062: A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple…
A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authenticated, local attacker with administrative privileges in one context to copy files to or from another context, including configuration files.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.22 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.22 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.22 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.22 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.22 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.22 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.23 | See the advisory |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.23 | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authenticated, local attacker with administrative privileges in one context to copy files to or from another context, including configuration files. This vulnerability is due to improper access controls for Secure Copy Protocol (SCP) operations when the CiscoSSH stack is enabled. An attacker could exploit this vulnerability by authenticating to a non-admin context of the device and issuing crafted SCP copy commands in that non-admin context. A successful exploit could allow the attacker to read, create, or overwrite sensitive files that belong to another context, including the admin and system contexts. The attacker cannot directly impact the availability of services pertaining to other contexts. To exploit this vulnerability, the attacker must have valid administrative credentials for a non-admin context. Note: An attacker cannot list or enumerate files from another context and would need to know the exact file path, which increases the complexity of a successful attack.
Exploitation
The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.