Cisco Firepower Threat Defense (FTD)
Our sources currently list 261 known vulnerabilities affecting Cisco Firepower Threat Defense (FTD). 6 are rated critical severity. 12 of 261 are actively exploited according to CISA, the most recent added 25 September 2025.
Last updated: 22 July 2026, 20:03 AEST
Australian advisories
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2021-44228 | Critical (10.0) | Actively exploited · ransomware | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai… | |
| CVE-2023-44487 | High (7.5) | Actively exploited | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through… | |
| CVE-2020-3452 | High (7.5) | Actively exploited | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, … | |
| CVE-2018-0296 | High (7.5) | Actively exploited | A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpected… | |
| CVE-2025-20362 | Medium (6.5) | Actively exploited | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by… | |
| CVE-2020-3580 | Medium (6.1) | Actively exploited · ransomware | Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthen… | |
| CVE-2020-3259 | High (7.5) | Actively exploited · ransomware | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, … | |
| CVE-2024-20353 | High (8.6) | Actively exploited | A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthen… | |
| CVE-2025-20333 | Critical (9.9) | Actively exploited | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an aut… | |
| CVE-2023-20269 | Medium (5.0) | Actively exploited · ransomware | A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticate… | |
| CVE-2024-20359 | Medium (6.0) | Actively exploited | A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software a… | |
| CVE-2024-20481 | Medium (5.8) | Actively exploited | A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauth… | |
| CVE-2020-3187 | Critical (9.1) | Elevated likelihood (97%) | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, … | |
| CVE-2018-0101 | Critical (10.0) | Elevated likelihood (87%) | A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause… | |
| CVE-2022-20759 | High (8.8) | Elevated likelihood (29%) | A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c… | |
| CVE-2022-20866 | High (7.4) | Elevated likelihood (17%) | A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an una… | |
| CVE-2019-1978 | Medium (5.8) | No exploitation reported | A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Soft… | |
| CVE-2025-20363 | Critical (9.0) | No exploitation reported | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Ci… | |
| CVE-2018-0231 | High (8.6) | No exploitation reported | A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an u… | |
| CVE-2018-15454 | High (8.6) | No exploitation reported | A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software cou… | |
| CVE-2019-15992 | High (7.2) | No exploitation reported | A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could … | |
| CVE-2018-0240 | High (8.6) | No exploitation reported | Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software … | |
| CVE-2020-3304 | High (8.6) | No exploitation reported | A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker… | |
| CVE-2018-0228 | High (8.6) | No exploitation reported | A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase u… | |
| CVE-2019-1687 | High (7.5) | No exploitation reported | A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated… | |
| CVE-2019-1703 | High (8.6) | No exploitation reported | A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated,… | |
| CVE-2020-3554 | High (7.5) | No exploitation reported | A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, r… | |
| CVE-2019-1694 | High (8.6) | No exploitation reported | A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, r… | |
| CVE-2018-15383 | High (7.5) | No exploitation reported | A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow a… | |
| CVE-2017-6632 | High (7.5) | No exploitation reported | A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote a… | |
| CVE-2021-40114 | Medium (6.8) | No exploitation reported | Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a… | |
| CVE-2020-3299 | Medium (5.8) | No exploitation reported | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HT… | |
| CVE-2019-1691 | Medium (5.8) | No exploitation reported | A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an unauthenticated, remote attacker to cause the unexpected restart of the SNORT dete… | |
| CVE-2019-1704 | High (7.5) | No exploitation reported | Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, … | |
| CVE-2020-3550 | High (8.1) | No exploitation reported | A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attac… | |
| CVE-2020-3315 | Medium (5.3) | No exploitation reported | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on… | |
| CVE-2021-1236 | Medium (5.3) | No exploitation reported | Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured poli… | |
| CVE-2020-3196 | High (8.6) | No exploitation reported | A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD… | |
| CVE-2019-1693 | Medium (6.5) | No exploitation reported | A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote att… | |
| CVE-2018-15462 | High (8.6) | No exploitation reported | A vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco Firepower Threat Defense (FTD) Software could allow an unauth… | |
| CVE-2018-0227 | High (7.5) | No exploitation reported | A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an… | |
| CVE-2019-1708 | High (8.6) | No exploitation reported | A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepow… | |
| CVE-2019-1697 | Medium (6.8) | No exploitation reported | A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (… | |
| CVE-2021-1224 | Medium (5.8) | No exploitation reported | Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remot… | |
| CVE-2021-1223 | High (7.5) | No exploitation reported | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HT… | |
| CVE-2019-1714 | High (8.6) | No exploitation reported | A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisc… | |
| CVE-2018-15388 | High (8.6) | No exploitation reported | A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, re… | |
| CVE-2019-15256 | High (8.6) | No exploitation reported | A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could a… | |
| CVE-2019-12698 | High (7.5) | No exploitation reported | A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote a… | |
| CVE-2020-3283 | High (8.6) | No exploitation reported | A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 S… |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
12 of these are being actively exploited right now.
Our Newcastle team can audit your Cisco estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
