Cisco Firepower Threat Defense (FTD)

Our sources currently list 261 known vulnerabilities affecting Cisco Firepower Threat Defense (FTD). 6 are rated critical severity. 12 of 261 are actively exploited according to CISA, the most recent added 25 September 2025.

Last updated: 22 July 2026, 20:03 AEST

ASD’s ACSC advisory

New steps for organisations running Cisco Firepower and Secure Firewall products

Published 2026-04-24 by the Australian Signals Directorate’s Australian Cyber Security Centre · references CVE-2025-20333, CVE-2025-20362

Known vulnerabilities in Cisco Firepower Threat Defense (FTD), highest risk first.Showing the 50 highest-risk of 261 total.
CVESeverityExploitationPublishedSummary
CVE-2021-44228Critical (10.0)Actively exploited · ransomwareApache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai…
CVE-2023-44487High (7.5)Actively exploitedThe HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through…
CVE-2020-3452High (7.5)Actively exploitedA vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, …
CVE-2018-0296High (7.5)Actively exploitedA vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpected…
CVE-2025-20362Medium (6.5)Actively exploitedUpdate: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by…
CVE-2020-3580Medium (6.1)Actively exploited · ransomwareMultiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthen…
CVE-2020-3259High (7.5)Actively exploited · ransomwareA vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, …
CVE-2024-20353High (8.6)Actively exploitedA vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthen…
CVE-2025-20333Critical (9.9)Actively exploitedA vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an aut…
CVE-2023-20269Medium (5.0)Actively exploited · ransomwareA vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticate…
CVE-2024-20359Medium (6.0)Actively exploitedA vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software a…
CVE-2024-20481Medium (5.8)Actively exploitedA vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauth…
CVE-2020-3187Critical (9.1)Elevated likelihood (97%)A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, …
CVE-2018-0101Critical (10.0)Elevated likelihood (87%)A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause…
CVE-2022-20759High (8.8)Elevated likelihood (29%)A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c…
CVE-2022-20866High (7.4)Elevated likelihood (17%)A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an una…
CVE-2019-1978Medium (5.8)No exploitation reportedA vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Soft…
CVE-2025-20363Critical (9.0)No exploitation reportedA vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Ci…
CVE-2018-0231High (8.6)No exploitation reportedA vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an u…
CVE-2018-15454High (8.6)No exploitation reportedA vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software cou…
CVE-2019-15992High (7.2)No exploitation reportedA vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could …
CVE-2018-0240High (8.6)No exploitation reportedMultiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software …
CVE-2020-3304High (8.6)No exploitation reportedA vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker…
CVE-2018-0228High (8.6)No exploitation reportedA vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase u…
CVE-2019-1687High (7.5)No exploitation reportedA vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated…
CVE-2019-1703High (8.6)No exploitation reportedA vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated,…
CVE-2020-3554High (7.5)No exploitation reportedA vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, r…
CVE-2019-1694High (8.6)No exploitation reportedA vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, r…
CVE-2018-15383High (7.5)No exploitation reportedA vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow a…
CVE-2017-6632High (7.5)No exploitation reportedA vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote a…
CVE-2021-40114Medium (6.8)No exploitation reportedMultiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a…
CVE-2020-3299Medium (5.8)No exploitation reportedMultiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HT…
CVE-2019-1691Medium (5.8)No exploitation reportedA vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an unauthenticated, remote attacker to cause the unexpected restart of the SNORT dete…
CVE-2019-1704High (7.5)No exploitation reportedMultiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, …
CVE-2020-3550High (8.1)No exploitation reportedA vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attac…
CVE-2020-3315Medium (5.3)No exploitation reportedMultiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on…
CVE-2021-1236Medium (5.3)No exploitation reportedMultiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured poli…
CVE-2020-3196High (8.6)No exploitation reportedA vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD…
CVE-2019-1693Medium (6.5)No exploitation reportedA vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote att…
CVE-2018-15462High (8.6)No exploitation reportedA vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco Firepower Threat Defense (FTD) Software could allow an unauth…
CVE-2018-0227High (7.5)No exploitation reportedA vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an…
CVE-2019-1708High (8.6)No exploitation reportedA vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepow…
CVE-2019-1697Medium (6.8)No exploitation reportedA vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (…
CVE-2021-1224Medium (5.8)No exploitation reportedMultiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remot…
CVE-2021-1223High (7.5)No exploitation reportedMultiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HT…
CVE-2019-1714High (8.6)No exploitation reportedA vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisc…
CVE-2018-15388High (8.6)No exploitation reportedA vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, re…
CVE-2019-15256High (8.6)No exploitation reportedA vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could a…
CVE-2019-12698High (7.5)No exploitation reportedA vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote a…
CVE-2020-3283High (8.6)No exploitation reportedA vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 S…

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

12 of these are being actively exploited right now.

Our Newcastle team can audit your Cisco estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.