Different vulnerabilities
Of the remaining flaws, an additional six are rated ‘excessive’, with CVSS scores of between 7.2 and eight.6. These embody the Firewall Administration Middle SQL injection vulnerabilities CVE-2026-20001, CVE-2026-20002, and CVE-2026-20003, all remotely exploitable by an authenticated attacker. Once more, no workarounds are doable.
CVE-2026-20039, rated 8.6 (‘vital’), is a flaw affecting the VPN net server in Cisco Safe Firewall Adaptive Safety Equipment (ASA) Software program and Cisco Safe Firewall Risk Protection (FTD) Software program which may permit an unauthenticated attacker to induce a denial of service state.
Moreover, CVE-2026-20082, additionally rated 8.6, may permit an unauthenticated attacker to trigger incoming TCP SYN packets to be dropped incorrectly within the Cisco Safe Firewall Adaptive Safety Equipment (ASA) Software program.

