Cisco Secure Firewall Threat Defense with Firewall Device Manager, Version 10
This document contains release information for Cisco Secure Firewall Threat Defense with Secure Firewall Device Manager.
Note |
Version 10 begins a new release numbering scheme and cadence. For more information, see the Cisco's Next Generation Firewall Product Line Software Release and Sustaining Bulletin. |
Release Dates
|
Version |
Build |
Date |
Platforms: Upgrade |
Platforms: Reimage |
|---|---|---|---|---|
|
10.1.0 |
160 |
2026-09-21 |
Firewall Management Center All devices except Secure Firewall 200 |
Firewall Management Center All devices except Secure Firewall 200 |
|
681 |
2026-09-21 |
Secure Firewall 200 |
Secure Firewall 200 |
|
|
10.0.2 |
79 |
2026-09-15 |
Firewall Management Center All devices except Secure Firewall 200 |
Firewall Management Center All devices except Secure Firewall 200 |
|
564 |
2026-09-15 |
Secure Firewall 200 |
Secure Firewall 200 |
|
|
10.0.1 |
1 |
2026-02-18 |
Firewall Management Center |
Firewall Management Center |
|
10.0.0 |
141 |
2025-12-23 |
Firewall Management Center | Firewall Management Center |
|
140 |
2025-12-03 |
All devices except Secure Firewall 200 |
All devices except Secure Firewall 200 |
|
|
637 |
2025-12-03 |
Secure Firewall 200 |
Secure Firewall 200 |
Features
Features in Version 10.1
|
Feature |
Description |
|---|---|
|
Firewall and IPS Features |
|
|
User and identity mapping limits. |
Firewall Device Manager can download user information for up to 50,000 users from a realm. Firewall Threat Defense supports separate identity mapping limits by device model, ranging from 10,000 mappings on Secure Firewall 220 devices to 600,000 mappings on and 4245 devices. Identity mappings include users, groups, SXP/SGT mappings, endpoint profiles, and dynamic objects. |
Features in Version 10.0
Released: December 3, 2025
The following table lists the new features available in Firewall Threat Defense 10.0 when configured using the Firewall Device Manager.
|
Feature |
Description |
|---|---|
|
Hardware Features |
|
|
Secure Firewall 220. |
The Secure Firewall 220 is an affordable security appliance for branch offices and remote locations that balances cost and features. |
|
Public and Private Cloud |
|
|
Firewall Threat Defense Virtual for Microsoft Hyper-V. |
Firewall Threat Defense Virtual now supports Microsoft Hyper-V. |
|
End of support: VMware vSphere/VMware ESXi 6.5, 6.7, and 7.0. |
Upgrade impact. Upgrade VMware before you upgrade the software. We discontinued support for virtual deployments on VMware vSphere/VMware ESXi 6.5, 6.7, and 7.0. Upgrade your hosting environment to Version 8.0 before you upgrade any virtual appliance. Version restrictions: Versions 7.3.x and 7.4.1 are not qualified on VMware 8.0. If you run any of these versions, upgrade to VMware 8.0 first. Move to the next step as soon as possible. For best results, perform a multi-step upgrade: first the virtual appliance to 7.4.2–7.7.x, then VMware, then the virtual appliances again. |
|
Larger default disk size and the ability to resize the disk post-deployment for Firewall Threat Defense Virtual. |
Firewall Threat Defense Virtual supports dynamic disk expansion on all virtual platforms. This capability optimizes disk utilization on high-capacity systems (for example, systems with 64 vCPUs and 128 GB RAM), ensuring that large core dump files do not trigger disk-space alerts. The default disk size has also has changed. |
|
Unlimited performance tier (FTDvU) for VMware and KVM |
Firewall Threat Defense Virtual for VMware and KVM now support an unlimited performance tier (FTDvU). This tier does not rate limit and the RA VPN session limit depends on the allocated resources:
|
|
Secure Boot and UEFI firmware support |
Upgrade impact. You cannot revert from Version 10+ to Version 7.7 or earlier. Firewall Threat Defense Virtual is now compatible with UEFI-based virtual machines. This modern firmware interface replaces legacy BIOS, improves boot performance, and provides enhanced hardware/VM compatibility. Secure Boot ensures that only signed and trusted bootloaders, kernel modules, and drivers are executed when the VM starts. It improves the virtual appliances security. These changes mean that you cannot revert virtual firewalls from Version 10+ to Version 7.7 and earlier. After upgrade, we also recommend you migrate configurations to freshly deployed Version 10+ instances and decommission the old ones. |
|
Firewall and IPS Features |
|
|
Limit ciphers used for the Firewall Device Manager web server and the captive portal used for active authentication identity rules. |
You can limit which ciphers can be used when connecting to the Firewall Device Manager, or when users are prompted for active authentication by identity rules. By limiting the ciphers allowed, you can enforce stronger security requirements than the default ciphers. We added the Firewall Device Manager Web Server and Identity Web Server cards to the page. The previous SSL settings applied to remote access VPN connections only. |
|
VPN Features |
|
|
Disconnect remote access VPN sessions by removing the smart card. |
If you use smart cards for RA VPN connections, you can configure the group policy to disconnect if the smart card is removed. This feature is enabled by default on all group policies on upgrade. You can disable the feature, so that connections are not dropped on smart card removal. We added the Disconnect on Smart Card Removal option to the Session Settings in the RA VPN group policy configuration. |
|
Administrative Features |
|
|
Updated internet access requirements for Security Intelligence feeds. |
Upgrade impact. The system connects to new resources. The system now gets Security Intelligence feeds from the same place as URL filtering data:
The system no longer requires access to intelligence.sourcefire.com. |
|
TACACS+ server authentication, authorization, and accounting support for Firewall Device Manager HTTPS management connections. |
You can configure the Firewall Device Manager to use your TACACS+ servers to authenticate and authorize HTTPS connections to the Firewall Device Manager. You can also enable TACACS+ accounting for these connections. We added TACACS+ server and server group objects to the identity sources and updated the management system settings (, AAA Configuration tab) to allow the selection of a TACACS+ server group. |
Related updates and deprecations
Resolved Issues
Resolved issues in Version 10.1.0
This table lists the resolved security issues in this specific software release.
Table last updated: 2026-09-21
|
ID |
Headline |
|---|---|
|
ENH: Support for assigning BGP community value using new-format under Route-map object on FMC |
|
|
ENH: FMC/FDM should provide a way to disable WebVPN portal on FTD |
|
|
ENH: allow http-only-cookie for web connection |
|
|
CVE-2019-17567: apache2: Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configu |
|
|
Deploy failure after interface group or port value change in Netflow collector config or max collector limit of 5 is reached |
|
|
IPSEC: Simultaneous Rekeying for Same SAs Resulting in Deleting the Newly Negotiated SA Post rekey |
|
|
Disable csd/hostscan invokation for clientless/webvpn flow |
|
|
CVE-2024-47728: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-50014: linux-kernel: ext4: fix access to uninitialised lock in fc replay |
|
|
Component activemq 5.2.0 is greater than 10 years old and needs updated |
|
|
FMC shows warning alert in ACL rule when time range object is configured within FMC time zone |
|
|
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability |
|
|
CVE-2024-26669: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26792: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36903: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36927: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-40972: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-53215: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-56738: grub: GNU GRUB (aka GRUB2) through 2.12 does not use ... |
|
|
CVE-2024-57977: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57981: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21673: linux-kernel: In the Linux kernel, the following vuln... |
|
|
Security Zones show \"No Data\" when attempting to edit ACP policies rules in FMC GUI post 7.7 upgrade - Indexing issue |
|
|
Snort2|3 traceback in libdaq initialization phase after deployments |
|
|
CVE-2024-26844: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26853: linux-kernel: In the Linux kernel, the following vuln... |
|
|
Columns missing from event partitions |
|
|
CVE-2023-52939: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26759: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-8096: curl: When curl is told to use the Certificate Status ... |
|
|
ASA SSH login fails at the first attempt when it is integrated with DUO |
|
|
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them |
|
|
CVE-2022-49901: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-0395: glibc: When the assert() function in the GNU C Library... |
|
|
CVE-2025-0840: binutils: A vulnerability, which was classified as pro... |
|
|
CVE-2025-1795: python: During an address list folding when a separati... |
|
|
CVE-2025-3360: glib: A flaw was found in GLib. An integer overflow an... |
|
|
CVE-2025-4565: protobuf: Any project that uses Protobuf Pure-Python b... |
|
|
CVE-2025-4673: golang: Proxy-Authorization and Proxy-Authenticate hea... |
|
|
CVE-2025-4802: glibc: Untrusted LD_LIBRARY_PATH environment variable ... |
|
|
CVE-2025-6069: python: The html.parser.HTMLParser class had worse-cas... |
|
|
CVE-2025-21636: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21639: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21665: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21683: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21700: linux-kernel: In the Linux kernel, the following vuln... |
|
|
Deployment Failure After Removing An Object From ACL Used in DAP |
|
|
CVE-2025-5318: libssh: A flaw was found in the libssh library. An out... |
|
|
CVE-2025-21753: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21756: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21760: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21762: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21763: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21764: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21846: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21887: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21891: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21999: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22134: vim: When switching to other buffers using the :all c... |
|
|
CVE-2025-22871: golang: The net/http package improperly accepts a bar... |
|
|
CVE-2025-23048: apache-http-server: In some mod_ssl configurations on... |
|
|
CVE-2025-24014: vim: Vim is an open source, command line text editor.... |
|
|
CVE-2025-24855: libxslt: numbers.c in libxslt before 1.1.43 has a use... |
|
|
CVE-2025-24928: libxml2: libxml2 before 2.12.10 and 2.13.x before 2.1... |
|
|
CVE-2025-25724: libarchive: list_item_verbose in tar/util.c in libarc... |
|
|
CVE-2025-26603: vim: Vim is a greatly improved version of the good ol... |
|
|
CVE-2025-27423: vim: Vim is an open source, command line text editor.... |
|
|
CVE-2025-29768: vim: Vim, a text editor, is vulnerable to potential d... |
|
|
CVE-2025-46394: busybox: In tar in BusyBox through 1.37.0, a TAR arch... |
|
|
CVE-2025-47273: python-setuptools: setuptools is a package that allow... |
|
|
CVE-2025-48964: iputils: ping in iputils before 20250602 allows a den... |
|
|
CVE-2025-47907: golang: Cancelling a query (e.g. by cancelling the co... |
|
|
CVE-2025-49796: libxml2: A vulnerability was found in libxml2. Proces... |
|
|
CVE-2025-50181: urllib3: urllib3 is a user-friendly HTTP client libra... |
|
|
CVE-2025-53020: apache-http-server: Late Release of Memory after Effe... |
|
|
CVE-2025-53905: vim: Vim is an open source, command line text editor.... |
|
|
CVE-2025-53906: vim: Vim is an open source, command line text editor.... |
|
|
CVE-2024-0397: python: A defect was discovered in the Python \u201cssl\u201d mo... |
|
|
CVE-2024-0450: python: An issue was found in the CPython `zipfile` mo... |
|
|
CVE-2024-1441: libvirt: An off-by-one error flaw was found in the ude... |
|
|
CVE-2024-1737: bind: Resolver caches and authoritative zone databases... |
|
|
CVE-2024-1975: bind: If a server hosts a zone containing a \"KEY\" Reso... |
|
|
CVE-2024-3447: qemu: A heap-based buffer overflow was found in the SD... |
|
|
CVE-2024-4032: python: The \u201cipaddress\u201d module contained incorrect inf... |
|
|
CVE-2024-4076: bind: Client queries that trigger serving stale data a... |
|
|
CVE-2024-6345: python-setuptools: A vulnerability in the package_inde... |
|
|
CVE-2024-6505: qemu: A flaw was found in the virtio-net device in QEM... |
|
|
CVE-2024-6923: python: There is a MEDIUM severity vulnerability affec... |
|
|
CVE-2024-7264: curl: libcurl's ASN1 parser code has the `GTime2str()`... |
|
|
CVE-2024-8088: python: CPython \"zipfile\" module affecting \"zipfile.Path\" |
|
|
CVE-2024-8354: qemu: A flaw was found in QEMU. An assertion failure w... |
|
|
CVE-2024-10041: pam: A vulnerability was found in PAM. The secret inf... |
|
|
CVE-2024-10524: wget: Applications that use Wget to access a remote r... |
|
|
CVE-2024-11187: bind: It is possible to construct a zone such that so... |
|
|
CVE-2024-12705: bind: Clients using DNS-over-HTTPS (DoH) can exhaust ... |
|
|
CVE-2024-24783: golang: Verifying a certificate chain which contains ... |
|
|
CVE-2024-24784: golang: The ParseAddressList function incorrectly han... |
|
|
CVE-2024-24785: golang: If errors returned from MarshalJSON methods c... |
|
|
CVE-2024-24791: golang: The net/http HTTP/1.1 client mishandled the c... |
|
|
CVE-2024-26676: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26718: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26726: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26756: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26924: linux-kernel: In the Linux kernel, the following vuln... |
|
|
ASA/FTD: might traceback and reload in asacli process when deploying/committing config session changes to ACLs with object-groups |
|
|
Verifying a certificate chain which contains a certificate with an unkno |
|
|
If errors returned from MarshalJSON methods contain user controlled data |
|
|
When following an HTTP redirect to a domain which is not a subdomain mat |
|
|
CVE-2025-1215: vim: A vulnerability classified as problematic was fou... |
|
|
CVE-2025-7424: libxslt: A flaw was found in the libxslt library. The ... |
|
|
CVE-2025-8114: libssh: A flaw was found in libssh, a library that imp... |
|
|
CVE-2025-32988: gnutls: A flaw was found in GnuTLS. A double-free vul... |
|
|
CVE-2025-32989: gnutls: A heap-buffer-overread vulnerability was foun... |
|
|
CVE-2025-32990: gnutls: A heap-buffer-overflow (off-by-one) flaw was ... |
|
|
CVE-2024-33655: unbound: The DNS protocol in RFC 1035 and updates all... |
|
|
CVE-2024-34156: golang: Calling Decoder.Decode on a message which con... |
|
|
CVE-2024-34397: glib: An issue was discovered in GNOME GLib before 2.... |
|
|
CVE-2024-34459: libxml2: An issue was discovered in xmllint (from lib... |
|
|
CVE-2024-35857: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-35865: linux-kernel: In the Linux kernel, the following vuln... |
|
|
XZ Utils provide a general-purpose data-compression library plus command |
|
|
Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allow |
|
|
Allocation of Resources Without Limits or Throttling vulnerability in Le |
|
|
json-path v2.8.0 was discovered to contain a stack overflow via the Crit |
|
|
ASA/FTD - 1550 Block Depletion Due to Instability of TCP Syslog Channel(s) |
|
|
FP3100/4200 FATAL - KC50 NIC pipe 0: QDMA Credit Update Error |
|
|
CVE-2024-25176: luajit: LuaJIT through 2.1 and OpenRusty luajit2 befo... |
|
|
CVE-2024-25178: luajit: LuaJIT through 2.1 and OpenRusty luajit2 befo... |
|
|
CVE-2024-35960: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38541: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38612: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-38352: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-35955: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38573: linux-kernel: In the Linux kernel, the following vuln... |
|
|
RADIUS external auth doing one request per interface when bad username/password attempted |
|
|
Missing Policy Based Routes on FMC PBR Page |
|
|
FXOS:ASA SSH login fails at the first attempt when it is integrated with DUO |
|
|
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTM |
|
|
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTM |
|
|
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTM |
|
|
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user |
|
|
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user |
|
|
In all versions of the package jspdf, it is possible to use < < script >scr |
|
|
In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL |
|
|
axios is a promise based HTTP client for the browser and node.js. The is |
|
|
axios 1.7.2 allows SSRF via unexpected behavior where requests for path |
|
|
Axios is a promise based HTTP client for the browser and Node.js. When A |
|
|
DOMPurify before 3.2.4 has an incorrect template literal regular express |
|
|
FTD traceback and reload on DATAPATH |
|
|
FTD traceback witnessed during/after deployment |
|
|
Lina: Traceback and reload for watchdog on BGP |
|
|
FTD - Missing KEX Algorithms |
|
|
Display a more informative message for FP 6100 on running show version before registering to an FMC |
|
|
FPR-4200: Port-channel flaps while generating chassis FPRM |
|
|
MariaDB cores due to conflicting queries on VPN_TUNNEL_STATUS |
|
|
FMC should fail the policy deployment in case of any interface/zone installation issues. |
|
|
Cannot replace FDM UI certificate due to \"SSP Server Unavailable\" error |
|
|
ASP ACL rule (dhcp network scope) fail to be removed during \"no nameif\" or interface deletion process |
|
|
Snort3 crash when SSL inspector receives a malformed packet for processing |
|
|
Few FQDNs are not resolving after FTD upgrade |
|
|
FMC unified events exclude filtering is not working when integrated with SAL |
|
|
Deployment Failure soon After Removing An Object From ACL Used in DAP even before commit |
|
|
High System CPU due to ActionQueueScrape and RNA Message Processing. |
|
|
Restarting Talos agent process leads to resetting the talos agent health file |
|
|
Multiple issues with either Interface not coming up or CRC errors with 25/50G LR SFP |
|
|
SNMP polling fails to work after upgrade |
|
|
Unable to save the ACL on cdFMC |
|
|
ASA/FTD - 'logging tcp-block-reduction' CLI Commands for TCP Syslog Queue Management |
|
|
ASA/FTD responding without relay_sig parameter in SAML dupicate request |
|
|
Lina engine traceback, due to assertion in datapath. |
|
|
While in App-Sync phase, cluster node does not transition to disabled state when CCL interface goes down |
|
|
Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Memory Exhaustion Denial of Service Vulnerability |
|
|
Lina Traceback & Reload On Thread Name: Reload Control Thread - After a reboot sequence |
|
|
Enable out of order packet discovery by default in appid |
|
|
Snort 3 Rule update not working if version field not updated |
|
|
Some Objects Not Available for Selection in Event Search Filters |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability |
|
|
Lina: asacli Traceback & reload due to SSH/SCP initiated from firewall exec mode |
|
|
ASA/FTD Continuous tracebacks and reloads after pushing the RAVPN & Identity SAML CP config |
|
|
jackson-core contains core low-level incremental (\"streaming\") parser an |
|
|
Allocation of resources for multipart headers with insufficient limits e |
|
|
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25 |
|
|
Versions of the package validator before 13.15.22 are vulnerable to Inco |
|
|
js-yaml is a JavaScript YAML parser and dumper. In js-yaml 4.1.0 and bel |
|
|
PCRE before 8.38 mishandles certain repeated conditional groups, which a |
|
|
Any project that parses untrusted Protocol Buffers data containing an ar |
|
|
Vulnerability in the MySQL Server product of Oracle MySQL (component: Cl |
|
|
Applications and libraries which misuse connection.serverAuthenticate (v |
|
|
A denial-of-service vulnerability exists in github.com/sirupsen/logrus w |
|
|
An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite |
|
|
Any project that uses Protobuf Pure-Python backend to parse untrusted Pr |
|
|
Issue summary: Calling the OpenSSL API function SSL_free_buffers may cau |
|
|
Go JOSE provides an implementation of the Javascript Object Signing and |
|
|
The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Pyth |
|
|
urllib3 is a user-friendly HTTP client library for Python. Starting in v |
|
|
urllib3 is a user-friendly HTTP client library for Python. Starting in v |
|
|
urllib3 is an HTTP client library for Python. urllib3's streaming API is |
|
|
A malformed DNS message in response to a query can cause the Lookup func |
|
|
A vulnerability in the package_index module of pypa/setuptools versions |
|
|
A parsing vulnerability for the MessageSet type in the ProtocolBuffers v |
|
|
CVE-2023-6395 The Mock software contains a vulnerability wherein an attacker could pot |
|
|
Integer overflow in the Safestring library maintained by Intel(R) may al |
|
|
CVE-2022-40899: future: An issue discovered in Python Charmers Future... |
|
|
CVE-2023-42363: busybox: A use-after-free vulnerability was discovere... |
|
|
CVE-2023-42364: busybox: A use-after-free vulnerability in BusyBox v.... |
|
|
CVE-2023-42365: busybox: A use-after-free vulnerability was discovere... |
|
|
CVE-2023-42366: busybox: A heap-buffer-overflow was discovered in Bus... |
|
|
CVE-2022-48666: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2022-48744: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2022-49267: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2022-49465: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2022-49651: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2022-49961: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26921: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26923: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26988: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-31076: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-33621: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-35962: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-35969: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-35970: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36017: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36621: docker: moby v25.0.5 is affected by a Race Condition ... |
|
|
CVE-2024-36898: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36957: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36964: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38580: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38596: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38601: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38659: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-40635: containerd: containerd is an open-source container ru... |
|
|
CVE-2024-40927: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-40953: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-40989: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-41013: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-41014: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-41045: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-42322: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-42516: apache-http-server: HTTP response splitting in the co... |
|
|
CVE-2024-43204: apache-http-server: SSRF in Apache HTTP Server with m... |
|
|
CVE-2024-43374: vim: The UNIX editor Vim prior to version 9.1.0678 ha... |
|
|
CVE-2024-45777: grub2: A flaw was found in grub2. The calculation of ... |
|
|
CVE-2024-45780: grub2: A flaw was found in grub2. When reading tar fi... |
|
|
CVE-2024-46752: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-46753: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-47081: python-requests: Requests is a HTTP library. Due to a... |
|
|
CVE-2024-47252: apache-http-server: Insufficient escaping of user-sup... |
|
|
CVE-2024-47619: syslog-ng: syslog-ng is an enhanced log daemo. Prior ... |
|
|
CVE-2024-47814: vim: Vim is an open source, command line text editor.... |
|
|
CVE-2024-50199: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-50602: python: An issue was discovered in libexpat before 2.... |
|
|
CVE-2024-52332: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-53125: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-53241: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-53680: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-55549: libxslt: xsltGetInheritedNsList in libxslt before 1.1... |
|
|
CVE-2024-56584: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57883: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57884: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57903: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57917: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57929: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57979: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-58083: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-58090: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-58093: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-7254: protobuf: Any project that parses untrusted Protocol B... |
|
|
CVE-2025-21701: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21702: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21719: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21839: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21971: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21975: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22045: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22055: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22058: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22075: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22086: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22111: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22121: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-23138: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-23141: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-23143: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-23150: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-23163: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37738: linux-kernel: In the Linux kernel, the following vuln... |
|
|
ASA/FTD traceback and reload after applying capture type isakmp command from LINA CLI |
|
|
Snort3 IPS policy DELETE Call failing internally leaving IPS policy corrupted. |
|
|
CVE-2025-37780: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37786: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37797: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37798: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37808: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37823: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37830: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37839: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37849: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37859: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37867: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37885: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37890: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37905: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37911: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37914: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37923: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37927: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37931: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37932: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37940: linux-kernel: In the Linux kernel, the following vuln... |
|
|
TCP Connection Not Closed Promptly with Flow Offload Due to Out-of-Order Teardown Packets on FTD/ASA |
|
|
A denial-of-service (DoS) vulnerability exists in google.protobuf.json_f |
|
|
CVE-2026-24049 wheel is a command line tool for manipulating Python wheel files |
|
|
Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before |
|
|
Unable to Access the Access Control Policy. |
|
|
Traceback at Process Name: lina < ctm_cryptodev_terminate_session+168 > |
|
|
Traffic is not hitting the expected rule, instead hitting default deny rule. |
|
|
Unable to use newly created or system defined object IPv4-Private-All-RFC1918 as a filter in events |
|
|
Embryonic drop counters not incrementing when per-client embryonic limit is breached |
|
|
FTD should not honour a huge time jump from NTP |
|
|
CVE-2026-24061: inetutils: telnetd in GNU Inetutils through 2.7 allow... |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability |
|
|
FMC Health Monitoring Generates Excessive Alerts for Undo Log Size Threshold Set Too Low |
|
|
In a domain aware FMC environment, pre-deployment validation errors are seen due to sub-domain group policies referencing global Secure Client Profiles, complaining of invalid / non existing file entries |
|
|
Unauthenticated RCE as root in CSM CommonRPC due to remote GWT policy file inclusion and subsequent |
|
|
Unable to connect FTD from console , SSH , telnet |
|
|
Cloud de-registeration fails with \"Bad Result - No OK or Redirect exception\" |
|
|
FTD: Snort crash due to stuck thread |
|
|
FTD: Duplicate syslog messages sent to each configured syslog server when using management interface |
|
|
LDAP External Auth certificate upload fails for Basic Constraint validation |
|
|
FMC: Temporary SSL policy views does not get cleared after session ends |
|
|
CVE-2025-14087: glib: A flaw was found in GLib (Gnome Lib). This vuln... |
|
|
CVE-2025-68615: net-snmp: net-snmp is a SNMP application library, too... |
|
|
CVE-2026-0915: glibc: Calling getnetbyaddr or getnetbyaddr_r with a c... |
|
|
CVE-2026-21441: urllib3: urllib3 is an HTTP client library for Python... |
|
|
CVE-2026-22801: libpng: LIBPNG is a reference library for use in appl... |
|
|
CVE-2026-25646: libpng: LIBPNG is a reference library for use in appl... |
|
|
CVE-2025-5244: binutils: A vulnerability was found in GNU Binutils up... |
|
|
CVE-2025-5245: binutils: A vulnerability classified as critical has b... |
|
|
CVE-2025-8677: bind: Querying for records within a specially crafted ... |
|
|
CVE-2025-9086: curl: 1. A cookie is set using the `secure` keyword fo... |
|
|
CVE-2025-13151: libtasn: Stack-based buffer overflow in libtasn1 vers... |
|
|
CVE-2025-13601: glib: A heap-based buffer overflow problem was found ... |
|
|
CVE-2025-13836: python: When reading an HTTP response from a server, ... |
|
|
CVE-2025-15281: glibc: Calling wordexp with WRDE_REUSE in conjunction... |
|
|
Backup-Restore silent failure in Multi-Instance |
|
|
FMC find usage feature not showing all assigned ACP for random objects |
|
|
ISE Dynamic Authorization Failure (Reason 11118) due to Missing Message-Authenticator Attribute for CoA ACK |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability |
|
|
Clear the IPv4 rp_filter setting to allow FMC with dual management interfaces in same subnet |
|
|
ASA/FTD Traceback and reload in BGP |
|
|
Deployment fails when ACL remark exceeds 100 characters |
|
|
generate_certs.pl might fail if there is device template in the FMC. |
|
|
Snort crashes or a FATAL ERROR occurs after 255 reloads if ngfw.rules includes NCM(Non-contiguous netmask) |
|
|
BGP unexpectedly removes all routes from BGP table during failover tests. |
|
|
FPR4225 losing communication with netmod |
|
|
Memory leak in SSL Crypto linked to DTLS sessions. |
|
|
Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense |
|
|
FTD: Azure AD SAML Captive Portal authentication fails when RAVPN is configured with non-standard HTTPS port |
|
|
Pre-upgrade pruning does not clean /var/sf/cloud_download/tmp_cisco/, leading to /var disk exhaustion and upgrade failure |
|
|
Exception observed in policy deployment during upgrade |
|
|
FTD is not resolving several FQDN's for ACL's |
|
|
Snort GR Misclassification and Traffic Drops in Multi-VRF Hairpin Flows after Bulk FMC Deployment |
|
|
minimatch is a minimal matching utility for converting glob expressions |
|
|
minimatch is a minimal matching utility for converting glob expressions |
|
|
minimatch is a minimal matching utility for converting glob expressions |
|
|
qs parser does not enforce limits for comma separated values allowing attackers to cause denial-of-service via memory exhaustion. |
|
|
Cisco Secure Firewall Management Center Software Session Fixation Issue |
|
|
CVE-2024-22654: ssp-blade-os: tcpreplay v4.4.4 was discovered to cont... |
|
|
CVE-2025-55154: ssp-blade-os: ImageMagick is free and open-source sof... |
|
|
CVE-2025-55160: ssp-blade-os: ImageMagick is free and open-source sof... |
|
|
CVE-2026-0861: ssp-blade-os: Passing too large an alignment to the me... |
|
|
Snort3 Watchdog restart caused by a corrupted stream_tcp thread |
|
|
FTD Traffic failure due to 9344 block depletion in peer_proxy_tx_q_lw_rx |
|
|
remove diffie-hellman-group14-sha1 from ssh/sshd configuration |
|
|
FirePower Recommendations refresh can take 40+ minutes to complete |
|
|
Impact: The fix for CVE-2021-23337. lodash library vulnerable to Code Injection via _.template imports key names. |
|
|
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn |
|
|
Issue summary: Applications using RSASVE key encapsulation to establisha |
|
|
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 |
|
|
OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTele |
|
|
Control-plane ACL with permit|deny IP|ESP drops ESP packets arriving on data node |
|
|
Certificate fields not correctly displayed in FMC GUI when \": \" is used in subject attributes (e.g., OU) |
|
|
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Static Credential Vulnerability |
|
|
CVE-2026-27143 Arithmetic over induction variables in loops were not cor |
|
|
Unable to save FTD instance interface changes if chassis subinterface VLAN ID is changed in change management mode |
|
|
FMC HA: Increase sfipproxy DEFAULT_BUF_SIZE_TCP to improve replication resilience and prevent error 1595 during SRU installs |
|
|
Allow User Configuration to Restrict Number of Parallel Backups in Configuration File |
|
|
Cisco Adaptive Security Appliance and Secure Firewall Threat Defense SSL VPN Denial of Service Vulnerability |
|
|
In Active/Active multicontext HA, when \"Secondary\" switches to Active it immediately bounce back to Standby state. |
|
|
Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability |
|
|
Chassis interface tab is empty on source chassis post cross-chassis import |
|
|
CVE-2026-29063 Immutable.js provides many Persistent Immutable data stru |
|
|
CVE-2025-62718 Axios is a promise based HTTP client for the browser and |
|
|
FMC Rule Hit Count page loads incomplete rule set and generates incomplete CSV reports when launched from ACE context menu |
|
|
Cisco Secure Firewall Management Center Software Authenticated Privilege Escalation to Root Vulnerability |
|
|
FMC Standard ACL page fails with \"Failed to resolve STDACE BBs\" due to orphaned REFID entries in bb_acl_data |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability |
|
|
FTD Traffic failure due to 9344 block depletion in snp_fp_snort |
|
|
CVE-2026-42040 Axios is a promise based HTTP client for the browser and |
|
|
CVE-2026-41205 Mako is a template library written in Python. Prior to 1. |
|
|
Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Unauthorized Authentication Bypass Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability |
|
|
Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Single Sign-On Token Forgery of Administrator Account Vulnerability |
|
|
IGMP events are not generated with pre-filer policy |
|
|
Cisco Secure Firewall Management Center Software SQL Injection Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Deserialization Arbitrary Root Command Execution Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability |
|
|
FTD: Traceback and reload due DNS Snooping cache holds a very high reference count for non-configured domain (NSG or SDWAN-DIA) |
|
|
Evaluate Cisco FXOS for CVE-2026-31431 (Copy Fail) |
|
|
Evaluate Cisco Secure Firewall 1200 and Cisco Secure Firewall 200 for CVE-2026-31431 (Copy Fail) |
|
|
ASA: PBR - ISP1 is not taking precedence over ISP2 |
|
|
CVE-2026-43284: linux-kernel: In the Linux kernel, the following vul... |
|
|
CVE-2026-35414: CiscoSSH: Incorrect matching of authorized_keys principals=\"\" option when a certificate principal contains a comma |
|
|
CVE-2026-35388: CiscoSSH: Connection multiplexing confirmation (ask/autoask) was not checked for proxy-mode sessions (ssh -O proxy) |
|
|
CVE-2026-35387: CiscoSSH: Listing any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms allowed all ECDSA algorithms |
|
|
CVE-2026-35385: CiscoSSH: scp in legacy mode (-O) as root did not clear setuid/setgid bits on downloaded files |
|
|
CVE-2026-35385: CiscoSSH: Command execution via shell metacharacters in username with non-default %u token in ssh_config |
|
|
Cisco Secure Firewall Management Center Software Information Disclosure and Disk Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Low Privileged Arbitrary File Download Vulnerability |
|
|
CVE-2025-53101: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2025-54349: iperf: In iperf before 3.19.1, iperf_auth.c ha... |
|
|
CVE-2025-57807: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2025-61144: libtiff: libtiff up to v4.7.1 was discovered to ... |
|
|
CVE-2025-64459: django: An issue was discovered in 5.1 before 5... |
|
|
CVE-2025-68121: golang: During session resumption in crypto/tls... |
|
|
CVE-2025-69720: ncurses: The infocmp command-line tool in ncurse... |
|
|
CVE-2026-22770: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-2369: libsoup: A flaw was found in libsoup. An integer ... |
|
|
CVE-2026-23876: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-25898: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-25968: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-25983: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-25986: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-25987: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-26284: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-27459: pyopenssl: pyOpenSSL is a Python wrapper around th... |
|
|
CVE-2026-28780: apache-http-server: Heap-based Buffer Overflow vulnerabilit... |
|
|
CVE-2026-31682: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-32746: inetutils: telnetd in GNU inetutils through 2.7 al... |
|
|
CVE-2026-33186: grpc-go: gRPC-Go is the Go language implementati... |
|
|
CVE-2026-33845: gnutls: A flaw in GnuTLS DTLS handshake parsing... |
|
|
CVE-2026-42010: gnutls: A flaw was found in gnutls. Servers con... |
|
|
CVE-2026-43037: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43038: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43117: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43186: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43198: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43233: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43253: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43281: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43328: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43329: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43336: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43339: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43341: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43350: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43365: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43964: postfix: Postfix before 3.8.16, 3.9 before 3.9.1... |
|
|
CVE-2026-4424: libarchive: A flaw was found in libarchive. This hea... |
|
|
CVE-2026-4437: glibc: Calling gethostbyaddr or gethostbyaddr_r... |
|
|
CVE-2026-44431: urllib3: urllib3 is an HTTP client library for P... |
|
|
CVE-2026-46483: vim: Vim is an open source, command line tex... |
|
|
CVE-2026-4775: libtiff: A flaw was found in the libtiff library.... |
|
|
CVE-2026-4786: python: Mitgation of CVE-2026-4519 was incomplet... |
|
|
CVE-2026-4878: libcap: A flaw was found in libcap. A local unpr... |
|
|
CVE-2026-4890: dnsmasq: A Denial of Service (DoS) vulnerability ... |
|
|
CVE-2026-4892: dnsmasq: A heap-based out-of-bounds write vulnera... |
|
|
CVE-2026-5121: libarchive: A flaw was found in libarchive. On 32-bi... |
|
|
CVE-2026-5172: dnsmasq: A buffer overflow in dnsmasq\u0019s extract_a... |
|
|
CVE-2026-5435: glibc: The deprecated functions ns_printrrf, ns... |
|
|
CVE-2026-5450: glibc: Calling the scanf family of functions wi... |
|
|
CVE-2026-5928: glibc: Calling the ungetwc function on a FILE s... |
|
|
CVE-2026-6100: python: Use-after-free (UAF) was possible in the... |
|
|
CVE-2026-6276: curl: Using libcurl, when a custom `Host:` hea... |
|
|
CVE-2026-6846: zlib: A flaw was found in binutils. A heap-buf... |
|
|
CVE-2026-46300 \"Fragnesia,\" is a high-severity Local Privilege Escalation (LPE) vulnerability in the Linux kernel |
|
|
FTDv: Intel I350 PCI passthrough interfaces fail to initialize after upgrade to 7.6.x |
|
|
CVE-2023-52168: 7zip: The NtfsHandler.cpp NTFS handler in 7-Zip befor... |
|
|
CVE-2024-29506: ghostscript: Artifex Ghostscript before 10.03.0 has a... |
|
|
CVE-2024-29509: ghostscript: Artifex Ghostscript before 10.03.0 has a... |
|
|
CVE-2024-41671: twisted: Twisted is an event-based framework for inte... |
|
|
CVE-2024-52531: libsoup: GNOME libsoup before 3.6.1 allows a buffer o... |
|
|
CVE-2024-56201: jinja: Jinja is an extensible templating engine. In v... |
|
|
CVE-2025-27516: jinja2: Jinja is an extensible templating engine. Pri... |
|
|
CVE-2025-40778: bind: Under certain circumstances, BIND is too lenien... |
|
|
CVE-2025-40780: bind: In specific circumstances, due to a weakness in... |
|
|
CVE-2025-58098: apache-http-server: Apache HTTP Server 2.4.65 and ear... |
|
|
CVE-2025-59777: libmicrohttpd: NULL pointer dereference vulnerability... |
|
|
CVE-2025-61732: golang: A discrepancy between how Go and C/C++ commen... |
|
|
CVE-2025-66418: urllib3: urllib3 is a user-friendly HTTP client libra... |
|
|
CVE-2026-23455: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-23456: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-27140: golang: SWIG file names containing 'cgo' and well-cra... |
|
|
CVE-2026-31402: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-31414: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-31450: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-31588: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-31709: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-31788: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-31958: tornado: Tornado is a Python web framework and asynch... |
|
|
CVE-2026-34714: vim: Vim before 9.2.0272 allows code execution that h... |
|
|
CVE-2026-34982: vim: Vim is an open source, command line text editor.... |
|
|
CVE-2026-42944: unbound: NLnet Labs Unbound 1.14.0 up to and includin... |
|
|
CVE-2026-42959: unbound: NLnet Labs Unbound up to and including versi... |
|
|
CVE-2026-42960: unbound: NLnet Labs Unbound up to and including versi... |
|
|
CVE-2026-43048: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43112: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43139: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43158: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43187: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43190: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43383: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43452: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43466: linux-kernel: In the Linux kernel, the following vuln... |
|
|
FMC deploy change when adding a new IP local pool to a group policy (Existing VPN sessions are terminated due to no enable < vpn-interface > sent under webvpn) |
|
|
Implement a confirmation button between importing a chassis MI config and deploying |
|
|
CVE-2026-48818 |
|
|
CVE-2025-14017: curl: When doing multi-threaded LDAPS transfers (LDAP... |
|
|
CVE-2026-22007: openjdk-jre: Vulnerability in the Oracle Java SE, Ora... |
|
|
CVE-2026-22013: openjdk-jre: Vulnerability in the Oracle Java SE, Ora... |
|
|
CVE-2026-22016: openjdk-jre: Vulnerability in the Oracle Java SE, Ora... |
|
|
CVE-2026-22018: openjdk-jre: Vulnerability in the Oracle Java SE, Ora... |
|
|
CVE-2026-22021: openjdk-jre: Vulnerability in the Oracle Java SE, Ora... |
|
|
CVE-2026-34268: openjdk-jre: Vulnerability in the Oracle Java SE, Ora... |
|
|
CVE-2026-34282: openjdk-jre: Vulnerability in the Oracle Java SE, Ora... |
|
|
CVE-2026-54283 Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, bu |
|
|
FMC fails to upload AnyConnect/Secure Client images exceeding 200 MB |
|
|
Stale user with no role can casue ERROR 403 for some pages |
|
|
CVE-2024-46830: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-38320: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-38670: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-71137: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43503: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43071: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-53131: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-8924: curl: A flaw in curl\u2019s cookie parsing logic allows a m... |
|
|
Snort 3 memory usage increases after repeated host-attribute reloads |
|
|
CVE-2024-41996 Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-expone |
|
|
CVE-2024-28757 libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). |
|
|
CVE-2023-52425 libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed. |
|
|
CVE-2024-45492 An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX). |
|
|
CVE-2024-45491 An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX). |
|
|
CVE-2026-34520 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been p |
|
|
CVE-2026-24486 Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can writ |
|
|
CVE-2026-6100 Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered i |
|
|
CVE-2026-27459 pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL w |
|
|
CVE-2022-1473 The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process p |
|
|
CVE-2022-3358 OpenSSL supports creating a custom cipher via the legacy EVP_CIPHER_meth_new() function and associated function calls. This function was deprecated in OpenSSL 3.0 and application authors are instead encouraged to use the new provider me |
|
|
CVE-2022-3602 A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious ce |
|
|
CVE-2023-0216 An invalid pointer dereference on read can be triggered when anapplication tries to load malformed PKCS7 data with thed2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions.The result of the dereference is an application crash which c |
|
|
CVE-2023-0217 An invalid pointer dereference on read can be triggered when anapplication tries to check a malformed DSA public key by theEVP_PKEY_public_check() function. This will most likely leadto an application crash. This function can be called |
|
|
CVE-2023-0401 A NULL pointer can be dereferenced when signatures are beingverified on PKCS7 signed or signedAndEnveloped data. In case the hashalgorithm used for the signature is known to the OpenSSL library butthe implementation of the hash algorith |
|
|
CVE-2025-69223 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request tha |
|
|
CVE-2023-5363 Issue summary: A bug has been identified in the processing of key andinitialisation vector (IV) lengths. This can lead to potential truncationor overruns during the initialisation of some symmetric ciphers.Impact summary: A truncation |
|
|
CVE-2025-69227 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS attack when processing a POST body. I |
|
|
CVE-2025-69228 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an appl |
|
|
CVE-2026-22815 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.1 |
|
|
CVE-2026-32597 PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 \u00a74.1.11. When a JWS token contains a crit array listing extensions that PyJWT does no |
|
|
CVE-2026-34513 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched i |
|
|
CVE-2026-34515 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3 |
|
|
CVE-2026-34516 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a D |
|
|
CVE-2026-41066 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the |
|
|
CVE-2026-42561 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no |
|
|
CVE-2026-47265 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `co |
|
|
CVE-2026-50269 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. |
|
|
CVE-2026-53539 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire rema |
|
|
CVE-2026-54273 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use ex |
|
|
CVE-2026-54275 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the |
|
|
CVE-2026-54277 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using the optimised C parser (the default |
|
|
CVE-2026-54274 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vul |
|
|
CVE-2026-54279 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vul |
|
|
CVE-2026-54278 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a |
|
|
CVE-2026-54280 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or simil |
|
|
CVE-2026-48526 PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algori |
|
|
CVE-2026-34993 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be |
This table lists the resolved functional issues in this specific software release.
Table last updated: 2026-09-21
|
ID |
Headline |
|---|---|
|
FTD MI: \"Spurious Write to tap_M1 failed\" messages appear after configuring the Management1/2 eventing IP on dual-management-port platforms |
|
|
ENH: Implement a search filter option on the Static Route page under the Routing section in FMC. |
|
|
Attempting to change local user password throws role error |
|
|
API explorer error on VMware upgraded FMC Failed to load API definition. |
|
|
FXOS - DME crashes with NULL pointer dereference in SockBioHandle::accept() |
|
|
4200- Block 1550 depletion seen when Snort crashes |
|
|
Searching with '_3' returns multiple unrelated device matches within Device Listing page |
|
|
DAP NONE criteria is not working properly. |
|
|
10G_T_X SFP interfaces are not coming up in 10G speed. |
|
|
Security Analytics and Logging Configuration Overrides Syslog Configuration When Using Same IP with Different Ports |
|
|
Policy Deployment failure at 10% with error - Deployment halted due to interface data inconsistency in Firewall Management Center |
|
|
snmp: SNMP IPv6 polling failing on standby firewall Due to IPv6 assingment failed on nlp. |
|
|
SNORT going down after upgrading FTD in MI mode |
|
|
Deployment failed with \"Failed to get version upgrade information for device\" post FTD upgrade |
|
|
Prometheus not working on FMC and cdFMC due to too many open files. |
|
|
show inventory reports transceiver PID as numeric internal value instead of Cisco SKU |
|
|
WA-4215 - Traceback observed due to Block depletion in the 256 1550 and 9344 with UDP traffic |
|
|
Core-local block allocation failures causing intermittent packet loss |
|
|
FDM: Product License Registration (PLR) release code is truncated to 5 characters, preventing license return |
|
|
FTW interfaces go to disabled during bootup even though bypass is configured |
|
|
FMC GUI: \"Index Calculation Error\" when cloning/copying ACP rules after search in New UI |
|
|
ASA/FTD: FIN/PSH/ACK ignored by normalizer resulting in flow not moving to half-closed |
|
|
Stale session PID handling in expire-session.pl leads to incorrect process kills and service disruption |
|
|
routing: FTD DVTI hub leaves stale RIB routes with missing interface after tunnel flap |
|
|
FMC Site-to-Site VPN dashboard shows lower IPv4 VTI tunnel count than Site-to-Site VPN topology page for the same topology |
|
|
FTD continually fails to reconnect RabbitMQ after entering loop of failing to reconnect |
|
|
Global Search duplicates BuildingBlock search execution and uses inefficient group expansion |
|
|
40/100G Copper SFP may go down on upgrading to version 2.16 and above. |
|
|
Backend processing fail for Domain name change, update this process to revert the changes |
|
|
Events no longer populate under Unified or Connection Events pages after FMC upgrade |
|
|
FMC NAT \"huge IP-range\" warning silently regressed for non-2100/1000 series devices |
|
|
FMC may partially persist configuration when REST API session replacement overlaps activity approval, contributing to integrity and deployment failures with policy/configuration |
|
|
FTDv on AWS interface Buffer Allocation Becomes Insufficient When More Than Four Data Interfaces Are Active |
|
|
Inconsistent LSP Rule Counts in Intrusion Policies |
|
|
FMC Displays Green Status After Standby FTD is Removed from the Network |
|
|
PBR syslog 880001 can disrupt the sftunnel communication between FMC and FTD |
|
|
High CPU usage on idfw_proc |
|
|
FTD: Multi-Instance application instance flaps NOT_RESPONDING/ONLINE every ~80s when chassis port-channel is configured as data-sharing |
|
|
System support trace running in the background causes performance impact |
|
|
Security Intelligence feed updates may fail to download on FMC when a custom feed URL contains a hash character |
|
|
ASA incorrectly sends syslog 113034 during VPN connection setup |
|
|
Excessive logging by dnsproxy process in /opt/cisco/config/var/log/process_stdout.log files |
|
|
Files process_stderr.log and process_stdout.log in /opt/cisco/config/var/log/ are not rotated |
|
|
FMC shows generic error instead of specific validator message when configuring External Authentication |
|
|
SASE Topology Deployment State Shows as PENDING Due to Stale Database Entries After Unsuccessful Umbrella Deployment |
|
|
SMA heartbeats are delayed due to DME end processing delay due to NTP |
|
|
FMC UI - VPN configuration save takes very long |
|
|
FMC: Standby FMC should not download SRU package from cloud |
|
|
Backup failure on physical FTDs \u2014 \"Backup failed due to an internal error. Retry.\" |
|
|
FMC 7.2.x: SRU install silently empties ids_event_msg_map via mysql_auto_reconnect mid-transaction rollback |
|
|
Policy Report Displays Unintended Snort Rule Action Changes After Modifying a Single Snort Rule |
|
|
Devices show offline due to \"Appliance unreachable\" due to HMS deadlock inserting to DB |
|
|
Telemetry streaming to FMC fails due to continuous vFTD Vault process exits |
|
|
FTD-HA Creation in New Device Management GUI Fails to List Interfaces Beyond First 25 interfaces |
|
|
FMC: Deployment failure due to StackOverflowError caused by circular object reference |
|
|
ASAv Azure Marketplace deployment fails with OSProvisioningInternalError/OSProvisioningClientError when selecting ssh key authN method |
|
|
cdFMC OSPF \"Add Area\" dialog defaults Area ID to 1 instead of backbone area 0, causing permanent auth validation block on all interface saves |
|
|
Error Downloading Secure Client File on Object Management Page with No Notification of Proper Failure Reason |
|
|
Prometheus FD exceeded the limit causing system failures |
|
|
FMC 7.4.6: SNMP trap address count inflated by validation bug when object groups used as SNMP hosts \u2014 Platform Policy save blocked |
|
|
ASA: Scheduled reload (reload in / reload at) does not reboot device |
|
|
Traceback in thread name PIM IPv4 and reload on firewall |
|
|
ASA/FTD: Remote Access VPN unit may reload unexpectedly during a server-side TLS handshake when hardware-accelerated RSA signing is performed while a per-connection lock is held |
|
|
ASA incorrectly enforces EKU when issuing CA certificate lacks EKU extension, causing false certificate validation failures |
|
|
FTD running 7.6.4 pruning dameon terminating every 10 minutes |
|
|
Lina activates a disabled bgp neighbor when a description is added |
|
|
Existing users redirected to 403 after login due to stale homepage preference (/ddd/#FirewallPolicyList) |
|
|
Multi-AZ cluster deployment fails after shared VTEP objects lose BB IDs on cluster unregistration |
|
|
Specific SNMP or SSH configuration can result in connectivity failure to cluster data node management IP |
|
|
Bridge group nembers should not participate in multicast routing protocols |
|
|
FMC: IPS Policy Edit Resulting in No Enum Constant |
|
|
Snort 3 system-defined rule action override fails when the rule belongs to multiple same-named rule groups |
|
|
ungraceful shutdown/reboot of FMC may cause corruption to Vault keyring |
|
|
FTD Standby unit traceback and reload during HA route synchronization when EIGRP summary routes are rapidly added and removed |
|
|
cdFMC 10.0.95: cross launch FTD HA creation fails with CDO \"Error 0\" |
|
|
Block deployment if device is participating in VPN topology where data is corrupted (manifesting in a way that the topology isn't seen on the UI) |
|
|
Deployment should automatically recover from database deadlocks |
|
|
Last hit count is not updated for VPN Access-List |
|
|
FPR1200: speed nonegotiate on 1G fiber SFP not applied in hardware on an already-created port, link stays DOWN |
|
|
QoS policy deployment generates a malformed QoS rule when an interface is not present, reloading Snort. |
|
|
ASA: Traceback and reload if user enters blank password on first login. |
|
|
Security intelligence incorrect rule action with duplicate objects |
|
|
FMC-managed FTD backup retrieval writes 100 percent to SSH RSD but fails finalization because the final placeholder must be replaced by rename |
|
|
Scheduled multi-FTD backup task reports executed successfully after Retrieve to Management Center exhausts all transfer attempts |
|
|
FMC access control rule listing and Object Library load may log repeated TimeRange ClassCastException and return empty effective start and end dates |
|
|
[FMC] Tomcat OOM may trigger device de-registration with MISSING_IN_CSM error. |
|
|
Policy deployment fails because FMC generates incomplete \"no fec\" command for an FTD HA Link/State interface |
|
|
Intermittent TCP connections transitioning to a half-closed state with flow offload enabled |
|
|
Block automatic device cleanup while FMC HADC operations are in progress |
|
|
VPN Load-Balancing Cluster Topology Is Incomplete on Slave Members After Upgrade |
Resolved issues in Version 10.0.2
This table lists the resolved security issues in this specific software release.
Table last updated: 2026-09-16
|
Bug ID |
Headline |
|---|---|
|
CVE-2019-17567: apache2: Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configu |
|
|
Disable csd/hostscan invokation for clientless/webvpn flow |
|
|
CVE-2024-47728: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-50014: linux-kernel: ext4: fix access to uninitialised lock in fc replay |
|
|
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability |
|
|
CVE-2024-26669: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26792: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36903: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36927: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-40972: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-53215: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-56738: grub: GNU GRUB (aka GRUB2) through 2.12 does not use ... |
|
|
CVE-2024-57977: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57981: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21673: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26844: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26853: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2023-52939: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26759: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-8096: curl: When curl is told to use the Certificate Status ... |
|
|
CVE-2025-32414: libxml2: In libxml2 before 2.13.8 and 2.14.x before 2... |
|
|
CVE-2025-32415: libxml2: In libxml2 before 2.13.8 and 2.14.x before 2... |
|
|
CVE-2022-49901: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-0395: glibc: When the assert() function in the GNU C Library... |
|
|
CVE-2025-0840: binutils: A vulnerability, which was classified as pro... |
|
|
CVE-2025-0938: python: The Python standard library functions `urllib.... |
|
|
CVE-2025-1795: python: During an address list folding when a separati... |
|
|
CVE-2025-3360: glib: A flaw was found in GLib. An integer overflow an... |
|
|
CVE-2025-4138: python: Allows the extraction filter to be ignored, al... |
|
|
CVE-2025-4330: python: Allows the extraction filter to be ignored, al... |
|
|
CVE-2025-4516: python: There is an issue in CPython when using `bytes... |
|
|
CVE-2025-4517: python: Allows arbitrary filesystem writes outside the... |
|
|
CVE-2025-4565: protobuf: Any project that uses Protobuf Pure-Python b... |
|
|
CVE-2025-4673: golang: Proxy-Authorization and Proxy-Authenticate hea... |
|
|
CVE-2025-4802: glibc: Untrusted LD_LIBRARY_PATH environment variable ... |
|
|
CVE-2025-6069: python: The html.parser.HTMLParser class had worse-cas... |
|
|
CVE-2025-6965: sqlite: There exists a vulnerability in SQLite version... |
|
|
CVE-2025-8194: python: There is a defect in the CPython “tarfile” mod... |
|
|
CVE-2025-21636: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21639: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21665: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21683: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21700: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-5318: libssh: A flaw was found in the libssh library. An out... |
|
|
CVE-2025-21753: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21760: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21762: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21763: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21764: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21846: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21887: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21891: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21999: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22134: vim: When switching to other buffers using the :all c... |
|
|
CVE-2025-22871: golang: The net/http package improperly accepts a bar... |
|
|
CVE-2025-23048: apache-http-server: In some mod_ssl configurations on... |
|
|
CVE-2025-24014: vim: Vim is an open source, command line text editor.... |
|
|
CVE-2025-24855: libxslt: numbers.c in libxslt before 1.1.43 has a use... |
|
|
CVE-2025-24928: libxml2: libxml2 before 2.12.10 and 2.13.x before 2.1... |
|
|
CVE-2025-25724: libarchive: list_item_verbose in tar/util.c in libarc... |
|
|
CVE-2025-26603: vim: Vim is a greatly improved version of the good ol... |
|
|
CVE-2025-27423: vim: Vim is an open source, command line text editor.... |
|
|
CVE-2025-29768: vim: Vim, a text editor, is vulnerable to potential d... |
|
|
CVE-2025-46394: busybox: In tar in BusyBox through 1.37.0, a TAR arch... |
|
|
CVE-2025-47273: python-setuptools: setuptools is a package that allow... |
|
|
CVE-2025-48964: iputils: ping in iputils before 20250602 allows a den... |
|
|
CVE-2025-47907: golang: Cancelling a query (e.g. by cancelling the co... |
|
|
CVE-2025-49796: libxml2: A vulnerability was found in libxml2. Proces... |
|
|
CVE-2025-50181: urllib3: urllib3 is a user-friendly HTTP client libra... |
|
|
CVE-2025-53020: apache-http-server: Late Release of Memory after Effe... |
|
|
CVE-2025-53905: vim: Vim is an open source, command line text editor.... |
|
|
CVE-2025-53906: vim: Vim is an open source, command line text editor.... |
|
|
CVE-2024-0397: python: A defect was discovered in the Python “ssl” mo... |
|
|
CVE-2024-0450: python: An issue was found in the CPython `zipfile` mo... |
|
|
CVE-2024-1441: libvirt: An off-by-one error flaw was found in the ude... |
|
|
CVE-2024-1737: bind: Resolver caches and authoritative zone databases... |
|
|
CVE-2024-1975: bind: If a server hosts a zone containing a "KEY" Reso... |
|
|
CVE-2024-3447: qemu: A heap-based buffer overflow was found in the SD... |
|
|
CVE-2024-3651: idna: A vulnerability was identified in the kjd/idna l... |
|
|
CVE-2024-4032: python: The “ipaddress” module contained incorrect inf... |
|
|
CVE-2024-4076: bind: Client queries that trigger serving stale data a... |
|
|
CVE-2024-6345: python-setuptools: A vulnerability in the package_inde... |
|
|
CVE-2024-6505: qemu: A flaw was found in the virtio-net device in QEM... |
|
|
CVE-2024-6923: python: There is a MEDIUM severity vulnerability affec... |
|
|
CVE-2024-7264: curl: libcurl's ASN1 parser code has the `GTime2str()`... |
|
|
CVE-2024-8088: python: CPython "zipfile" module affecting "zipfile.Path" |
|
|
CVE-2024-8354: qemu: A flaw was found in QEMU. An assertion failure w... |
|
|
CVE-2024-10041: pam: A vulnerability was found in PAM. The secret inf... |
|
|
CVE-2024-10524: wget: Applications that use Wget to access a remote r... |
|
|
CVE-2024-11187: bind: It is possible to construct a zone such that so... |
|
|
CVE-2024-12705: bind: Clients using DNS-over-HTTPS (DoH) can exhaust ... |
|
|
CVE-2024-12718: python: Allows modifying some file metadata (e.g. las... |
|
|
CVE-2024-24783: golang: Verifying a certificate chain which contains ... |
|
|
CVE-2024-24784: golang: The ParseAddressList function incorrectly han... |
|
|
CVE-2024-24785: golang: If errors returned from MarshalJSON methods c... |
|
|
CVE-2024-24791: golang: The net/http HTTP/1.1 client mishandled the c... |
|
|
CVE-2024-26676: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26718: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26726: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26756: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26924: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-1215: vim: A vulnerability classified as problematic was fou... |
|
|
CVE-2025-7424: libxslt: A flaw was found in the libxslt library. The ... |
|
|
CVE-2025-8114: libssh: A flaw was found in libssh, a library that imp... |
|
|
CVE-2025-32988: gnutls: A flaw was found in GnuTLS. A double-free vul... |
|
|
CVE-2025-32989: gnutls: A heap-buffer-overread vulnerability was foun... |
|
|
CVE-2025-32990: gnutls: A heap-buffer-overflow (off-by-one) flaw was ... |
|
|
CVE-2024-33655: unbound: The DNS protocol in RFC 1035 and updates all... |
|
|
CVE-2024-34156: golang: Calling Decoder.Decode on a message which con... |
|
|
CVE-2024-34397: glib: An issue was discovered in GNOME GLib before 2.... |
|
|
CVE-2024-34459: libxml2: An issue was discovered in xmllint (from lib... |
|
|
CVE-2024-35857: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-35865: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-25176: luajit: LuaJIT through 2.1 and OpenRusty luajit2 befo... |
|
|
CVE-2024-25178: luajit: LuaJIT through 2.1 and OpenRusty luajit2 befo... |
|
|
CVE-2024-35960: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38541: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38612: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-38352: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-35955: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38573: linux-kernel: In the Linux kernel, the following vuln... |
|
|
RADIUS external auth doing one request per interface when bad username/password attempted |
|
|
MariaDB cores due to conflicting queries on VPN_TUNNEL_STATUS |
|
|
Restarting Talos agent process leads to resetting the talos agent health file |
|
|
Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Memory Exhaustion Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability |
|
|
Issue summary: Calling the OpenSSL API function SSL_free_buffers may cau |
|
|
CVE-2022-40899: future: An issue discovered in Python Charmers Future... |
|
|
CVE-2023-42363: busybox: A use-after-free vulnerability was discovere... |
|
|
CVE-2023-42364: busybox: A use-after-free vulnerability in BusyBox v.... |
|
|
CVE-2023-42365: busybox: A use-after-free vulnerability was discovere... |
|
|
CVE-2023-42366: busybox: A heap-buffer-overflow was discovered in Bus... |
|
|
CVE-2022-48666: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2022-48744: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2022-49267: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2022-49465: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2022-49651: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2022-49961: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26921: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-26988: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-31076: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-33621: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-35962: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-35969: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-35970: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36017: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36621: docker: moby v25.0.5 is affected by a Race Condition ... |
|
|
CVE-2024-36898: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36957: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-36964: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38580: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38596: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38601: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-38659: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-40635: containerd: containerd is an open-source container ru... |
|
|
CVE-2024-40927: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-40953: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-40989: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-41013: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-41014: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-41045: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-42322: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-42516: apache-http-server: HTTP response splitting in the co... |
|
|
CVE-2024-43204: apache-http-server: SSRF in Apache HTTP Server with m... |
|
|
CVE-2024-43374: vim: The UNIX editor Vim prior to version 9.1.0678 ha... |
|
|
CVE-2024-45777: grub2: A flaw was found in grub2. The calculation of ... |
|
|
CVE-2024-45780: grub2: A flaw was found in grub2. When reading tar fi... |
|
|
CVE-2024-46752: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-46753: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-47081: python-requests: Requests is a HTTP library. Due to a... |
|
|
CVE-2024-47252: apache-http-server: Insufficient escaping of user-sup... |
|
|
CVE-2024-47619: syslog-ng: syslog-ng is an enhanced log daemo. Prior ... |
|
|
CVE-2024-47814: vim: Vim is an open source, command line text editor.... |
|
|
CVE-2024-50199: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-50602: python: An issue was discovered in libexpat before 2.... |
|
|
CVE-2024-52332: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-53125: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-53241: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-53680: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-55549: libxslt: xsltGetInheritedNsList in libxslt before 1.1... |
|
|
CVE-2024-56584: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57883: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57884: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57903: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57917: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57929: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-57979: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-58083: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-58090: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-58093: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2024-7254: protobuf: Any project that parses untrusted Protocol B... |
|
|
CVE-2025-21701: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21702: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21719: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21839: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21971: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-21975: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22045: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22055: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22058: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22075: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22086: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22111: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-22121: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-23138: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-23143: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-23150: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-23163: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37738: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37780: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37786: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37797: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37798: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37808: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37823: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37830: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37839: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37849: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37859: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37867: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37885: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37890: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37905: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37911: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37914: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37923: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37927: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37931: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37932: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2025-37940: linux-kernel: In the Linux kernel, the following vuln... |
|
|
Traceback at Process Name: lina <ctm_cryptodev_terminate_session+168> |
|
|
CVE-2026-24061: inetutils: telnetd in GNU Inetutils through 2.7 allow... |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability |
|
|
CVE-2025-14087: glib: A flaw was found in GLib (Gnome Lib). This vuln... |
|
|
CVE-2025-68615: net-snmp: net-snmp is a SNMP application library, too... |
|
|
CVE-2026-0915: glibc: Calling getnetbyaddr or getnetbyaddr_r with a c... |
|
|
CVE-2026-21441: urllib3: urllib3 is an HTTP client library for Python... |
|
|
CVE-2026-22801: libpng: LIBPNG is a reference library for use in appl... |
|
|
CVE-2026-25646: libpng: LIBPNG is a reference library for use in appl... |
|
|
CVE-2025-5244: binutils: A vulnerability was found in GNU Binutils up... |
|
|
CVE-2025-5245: binutils: A vulnerability classified as critical has b... |
|
|
CVE-2025-8677: bind: Querying for records within a specially crafted ... |
|
|
CVE-2025-9086: curl: 1. A cookie is set using the `secure` keyword fo... |
|
|
CVE-2025-13151: libtasn: Stack-based buffer overflow in libtasn1 vers... |
|
|
CVE-2025-13601: glib: A heap-based buffer overflow problem was found ... |
|
|
CVE-2025-13836: python: When reading an HTTP response from a server, ... |
|
|
CVE-2025-15281: glibc: Calling wordexp with WRDE_REUSE in conjunction... |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability |
|
|
Clear the IPv4 rp_filter setting to allow FMC with dual management interfaces in same subnet |
|
|
Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense |
|
|
FTD: Azure AD SAML Captive Portal authentication fails when RAVPN is configured with non-standard HTTPS port |
|
|
Cisco Secure Firewall Management Center Software Session Fixation Issue |
|
|
CVE-2024-22654: ssp-blade-os: tcpreplay v4.4.4 was discovered to cont... |
|
|
CVE-2025-55154: ssp-blade-os: ImageMagick is free and open-source sof... |
|
|
CVE-2025-55160: ssp-blade-os: ImageMagick is free and open-source sof... |
|
|
CVE-2026-0861: ssp-blade-os: Passing too large an alignment to the me... |
|
|
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Static Credential Vulnerability |
|
|
Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Authenticated Privilege Escalation to Root Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability |
|
|
Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Unauthorized Authentication Bypass Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability |
|
|
Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Single Sign-On Token Forgery of Administrator Account Vulnerability |
|
|
Cisco Secure Firewall Management Center Software SQL Injection Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Deserialization Arbitrary Root Command Execution Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability |
|
|
Evaluate Cisco FXOS for CVE-2026-31431 (Copy Fail) |
|
|
CVE-2026-43284: linux-kernel: In the Linux kernel, the following vul... |
|
|
Cisco Secure Firewall Management Center Software Information Disclosure and Disk Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Low Privileged Arbitrary File Download Vulnerability |
|
|
CVE-2025-53101: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2025-54349: iperf: In iperf before 3.19.1, iperf_auth.c ha... |
|
|
CVE-2025-57807: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2025-61144: libtiff: libtiff up to v4.7.1 was discovered to ... |
|
|
CVE-2025-68121: golang: During session resumption in crypto/tls... |
|
|
CVE-2025-69720: ncurses: The infocmp command-line tool in ncurse... |
|
|
CVE-2026-22770: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-2369: libsoup: A flaw was found in libsoup. An integer ... |
|
|
CVE-2026-23876: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-25898: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-25968: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-25983: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-25986: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-25987: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-26284: image-magick: ImageMagick is free and open-source sof... |
|
|
CVE-2026-28780: apache-http-server: Heap-based Buffer Overflow vulnerabilit... |
|
|
CVE-2026-31682: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-32746: inetutils: telnetd in GNU inetutils through 2.7 al... |
|
|
CVE-2026-33186: grpc-go: gRPC-Go is the Go language implementati... |
|
|
CVE-2026-33845: gnutls: A flaw in GnuTLS DTLS handshake parsing... |
|
|
CVE-2026-42010: gnutls: A flaw was found in gnutls. Servers con... |
|
|
CVE-2026-43037: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43038: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43117: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43186: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43233: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43329: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43336: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43339: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43341: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43365: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-5121: libarchive: A flaw was found in libarchive. On 32-bi... |
|
|
CVE-2026-5450: glibc: Calling the scanf family of functions wi... |
|
|
CVE-2026-6100: python: Use-after-free (UAF) was possible in the... |
|
|
CVE-2026-23455: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-23456: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-31402: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-31450: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-31788: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-42960: unbound: NLnet Labs Unbound up to and including versi... |
|
|
CVE-2026-43187: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43190: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43383: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43452: linux-kernel: In the Linux kernel, the following vuln... |
|
|
CVE-2026-43466: linux-kernel: In the Linux kernel, the following vuln... |
|
|
FMC fails to upload AnyConnect/Secure Client images exceeding 200 MB |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability |
This table lists the resolved functional issues in this specific software release.
Table last updated: 2026-09-15
|
Bug ID |
Headline |
|---|---|
|
Device alerts ROMMON upgrade failure though the upgrade is successful |
|
|
FTD may drop traffic in the Azure cloud at mlx5 driver level. |
|
|
System calls may be delayed due to printing of ECC errors on console |
|
|
API explorer error on VMware upgraded FMC Failed to load API definition. |
|
|
[NGFW][Azure]FMC/FTD deployment fails for 3 times due to process restarted |
|
|
WM/ASAc Lina Crash in lina_extract_process_mem_usage |
|
|
FDM: FTD interfaces lost after configuration restore |
|
|
AC Policy Apply reuses rule ids sometimes (Proper Fix) |
|
|
ASA on hyper-v: couldn't configure VLAN after upgrade |
|
|
Fatal error: Error running script 200_pre/500_stop_system.sh while upgrading FTD MI-HA |
|
|
RBAC: CSDAC Connector status shows "Unknown" for Read Only user |
|
|
FMC 10.0.0: SFDataCorrelator crashes with SIGSEGV in libmabain.so due to incompatible database header format after upgrade |
|
|
HA traffic being sent out to one TX queue causing high CPU and throughput limitation on CSF6170 |
|
|
"Deployment Preview, rollback version are missing resulting in preview , rollback functionality not working" |
|
|
TPK Rommon - Support Smart Modular DDR4 |
|
|
FTDv on AWS interface Buffer Allocation Becomes Insufficient When More Than Four Data Interfaces Are Active |
|
|
FTD may traceback and reload in thread name "DATAPATH" due to Snort pending verdict |
|
|
DHCP client getting disabled on the outside interface |
Resolved issues in Version 10.0.1
This table lists the resolved security issues in this specific software release.
Table last updated: 2026-03-04
|
ID |
Headline |
|---|---|
|
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability |
Resolved issues in Version 10.0.0
This table lists the resolved security issues in this specific software release.
Table last updated: 2026-3-16
|
ID |
Headline |
|---|---|
|
Order of access-list/ access-group is different in standby unit. Full sync happens during node-join. |
|
|
ASA/FTD traceback and reload when invoking "show webvpn saml idp" CLI command |
|
|
unable to edit standard access list objects |
|
|
Custom rule with "metadata:impact_flag red" in Snort3 not detected as Impact Level 1 |
|
|
Additional tab/space added in ACL logging messages in EMBLEM format causing ingestion issues |
|
|
Evaluation of multiple Azul Zulu vulnerabilities on openjre ASDM |
|
|
[FMC HA] Follower accepts data only from 1 leader |
|
|
Redis is an open source, in-memory database that persists on disk. An |
|
|
In the Linux kernel, the following vulnerability has been resolved: s |
|
|
ASA block depletion due to SSL pre auth connections |
|
|
FMC GUI does not Accept "@" in the username for remote storage used for backups |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software OSPF Heap Corruption Vulnerability |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software OSPF DoS Vulnerability |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software OSPF Memory Exhaustion Vulnerability |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software OSPF DoS Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability |
|
|
FMC Legacy UI allows you to create time range objects in past time in ACL |
|
|
FTD native: ldap configuration fails to deploy to ftd when using same user as radius |
|
|
Unable to load Extended ACL objects if the count is more than few hundreds |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerability |
|
|
FMC API put taking long time to update Extended ACL objects when count is huge like hundreds |
|
|
Firepower wiping SSL trustpoint config after reloading. |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability |
|
|
Memory leak in RAVPN |
|
|
Unable to save the Ext ACL object - "Only Host and Network in IPv4 and IPv6 format are supported." |
|
|
Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense Software HTTP Server Remote Code Execution Vulnerability |
|
|
Cisco Secure Firewall Management Center Software Command Injection Vulnerability |
|
|
IPv6 Management communication is lost due to a missing management-only multicast route. |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability |
|
|
ARP is silently dropping packet for an unreachable next hop |
|
|
Traceback & Reload in Thread Name Unicorn Admin Handler |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software IKEv2 DoS Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software Remote Access SSL VPN Authentication Denial of Service Vulnerability |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software Remote Access SSL VPN Memory Exhaustion Denial of Service Vulnerability |
|
|
Duplicate ACLs seen on FMC UI when Access Rules are created through API |
|
|
Cisco Secure Firewall Threat Defense Software Snort Deep Inspection Bypass Vulnerability |
|
|
Cisco Secure Firewall Threat Defense Software Geolocation Remote Access VPN Bypass Vulnerability |
|
|
Cisco Secure Firewall Management Center Software SQL Injection Vulnerabilities |
|
|
Snort2|3 traceback in libdaq initialization phase after deployments |
|
|
Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software Remote Access SSL VPN Unauthenticated Memory Exhaustion Denial of Service Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software Remote Access SSL VPN Lua Interpreter Denial of Service Vulnerability |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software Remote Access SSL VPN Authenticated Memory Exhaustion Denial of Service Vulnerability |
|
|
Cisco FXOS and UCS Manager Software Command Injection Vulnerability |
|
|
Cisco FXOS and UCS Manager Software Command Injection Vulnerability |
|
|
Traffic hits incorrect ACP rules during policy deployment on FTD with dynamic objects |
|
|
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability |
|
|
Lina: Traceback in thread name ssh on executing show access-list after ACL deletion |
|
|
Route map object ACL match clause overwrited in all route maps objects after saving changes. |
|
|
Remove unsafe directives from Content-Security-Policy header |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability |
|
|
ACL: ASA may show false "OOB Access-list config change detected" warning after AAA authorization command is applied |
|
|
Cleaning of /var/temp backup files post Backup completion not cleaning |
|
|
Cisco Secure Firewall Adaptive Security Appliance Software Multiple Context Mode SCP Unauthorized File Access Vulnerability |
|
|
Policy Deployment: When using MD5 in Site-to-Site VPN, manual deployment fails with validation error, but schedule deployment succeeds. |
|
|
Packet-tracer displaying incorrect ACL even though traffic action is taken based on the expected ACL. |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SAML Reflected Cross-Site Scripting Vulnerability |
|
|
Cisco Secure Firewall Threat Defense Software Snort Deep Inspection Bypass Vulnerability |
|
|
Reverting FTD upgrade silently removes object overrides on the FMC for the reverted FTD |
|
|
PAO logic for access rules POST/PUT api call for spaces in ip addresses in ACL rules |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Cross-Site Scripting Vulnerability |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software IKEv2 DoS Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Client-Side Request Smuggling Vulnerability |
|
|
External auth login with RADIUS to FMC UI may fail if Class attribute is used |
|
|
FMC RADIUS external authentication access requests missing 6 attributes after FMC upgrade |
|
|
Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities |
|
|
ASA from CSM/CLI - no access-list ACL_name line line_nr remark on last ACL line shows message - "Specified remark does not exist" |
|
|
Invalid host header reveals ASA interface IP address |
|
|
high cpu and high disk util fault as ucssh process is in never ending loop |
|
|
CVE-2025-32462: sudo: Before 1.9.17p1, allows users to execute commands on unintended machines. |
|
|
Inbound IPsec packets are dropped by IPsec offload when the crypto map ACL is using specific ports. |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software IKEv2 DoS Vulnerability |
|
|
Cisco Secure Firewall ASA Software and Secure FTD Software OSPF Memory Corruption Vulnerability |
|
|
RAVPN SSL/IKEV2 AUTH FAILURE: AAA PROCESS MISHANDLING BROKEN FIBER CLASS |
|
|
FMC: Copy/Cut/Paste or drag/drop ACE in Extended ACL object, deletes existing Rules |
|
|
Multiple Cisco Products Snort 3 DCERPC Vulnerabilities |
|
|
Multiple Cisco Products Snort 3 DCERPC Vulnerabilities |
|
|
Firewall joins a cluster although gets incomplete ACL policy rules during replication |
|
|
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability |
|
|
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability |
|
|
SAML response rejected with message for certain IDPs |
|
|
Drop counter doesn't increment for embryonic related drops in 'show service policy' |
|
|
Cisco Secure Firewall Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability |
|
|
Invalid OSPF process popup blocking route-map configuration |
|
|
FMC: Realm sync after import, un assigns IPS policies configured in ACEs |
|
|
Cisco Secure Firewall Adaptive Security Appliance Software TCP Flood Denial of Service Vulnerability |
|
|
uZTNA Private resource not working due to hztna CRT expiration on FTD |
|
|
SFDataCorrelator backtrace every 1 hour after VDB update on FMC |
|
|
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability |
|
|
FMC UI route-map access list stuck |
|
|
Rule mismatch based on Snort AC rule id duplication |
This table lists the resolved functional issues in this specific software release.
Table last updated: 2026-3-16
|
ID |
Headline |
|---|---|
|
"logging debug-trace persistent" fails for "debug ip ..." related debugs |
|
|
DP-CP arp-in and adj-absent queues need to be separated |
|
|
User-Role permission for Object-MGMT "Find-Usage" |
|
|
Write cache is disabled on some FMC M5 appliances |
|
|
Standby FTD/ASA sends DNS queries with source IP of 0.0.0.0 |
|
|
Inline pair has incorrect FTW bypass operation mode of 'Phy Bypass' |
|
|
ASA/FTD : High LINA memory observed after configuring multiple AnyConnect packages |
|
|
Last Synchronized date in FMC smart license status is not always accurate |
|
|
New realm user are incorrectly getting mapped to discovered user |
|
|
scheduled task may not run at all if UTC start times (based on DST) are on different calendar days |
|
|
FMC does not support Umbrella with proxy setting |
|
|
on 2k platform, external authentication fails for users starting with number |
|
|
Snort3 Rule Recommendations - add error message if Network Discovery is not configured |
|
|
Misleading error message while attemtping to revert upgrade on inelligible device |
|
|
External Auth on FMC may throw err "Can't use string ("") as a HASH ref while "strict refs" in use" |
|
|
The fxos directory disappears after cancelling show tech fprm detail command with Ctr+c is executed. |
|
|
Stale anyconnect entries causing issues with routing |
|
|
Edit search page and unified event viewer very slow to load due to high number of search-related EOs |
|
|
DAP: debug dap trace not fully shown after 3000+ lines |
|
|
ENH: Add a command or a script to regenerate CA Certificate on FTD |
|
|
snort3 crashes observed due to memory corruption in file api |
|
|
Lina traceback in ZMQ Proxy caused service loss. |
|
|
ASA: unexpected logs for initiating inbound connection for DNS query response |
|
|
Continuous High CPU usage Alerts on FP1010 |
|
|
ENH : ASDM does not accept VTI Interface for routes, CLI works |
|
|
3100/4200: qdma driver watchdog timeout |
|
|
FTD 7.4.1 Snort shows 100% utilization even at a low traffic rate |
|
|
Snort3 traceback and restarts with race conditions |
|
|
Error 403: Forbidden when tried to access certificate trustpoint enrolment page on FMC Domain user |
|
|
Fault "Adapter 1/x/y is unreachable" due to connectivity failure between supervisor and VIC adapter |
|
|
Applications are incorrectly identified as TOR and blocked by Snort3 |
|
|
Snort creating too many snort-unified log files when frequent policy deploys |
|
|
Snort3 traceback and reload due to memory corruption in file module |
|
|
Snort3 crashes due to processing pdf tokenizer with no limits. |
|
|
Object usages modal: white text on white background |
|
|
Snort3 crashes while collecting flow-ip-profiling |
|
|
Incorrect syslog generated on failure to process SGT from ISE during RA authentication |
|
|
SNMP for mgmt0/diagnostic outgoing traffic is missing |
|
|
WebEx traffic not getting bypassed in snort3 (allow rules) |
|
|
Virtual ASA/FTD may traceback and reload in thread PTHREAD |
|
|
FMC - HA || Fail with error: HA Sync Failed |
|
|
ASDM- Unable to edit Secure Client Profile |
|
|
FMC : DAP configuration "laggy/hangs" when trying to configure via FMC. |
|
|
Increase sftunnel AUTH_TIMEOUT to 60 |
|
|
debug menu command to prevent 1550 block depletion due to sendinglogs to TCP syslog server |
|
|
Snort AppID incorrectly identifies SSH traffic as Unknown |
|
|
Creating cluster bundle tar files for cluster failing with remote storage SSH configured |
|
|
FMC unable to search Objects when there is a DNS configured |
|
|
Add timestamps into bash_history |
|
|
S2S VPN config removed unexpectedly after deployment |
|
|
File Download fails intermittently with malware & file policy configured |
|
|
SSH access with public key authentication fails after FXOS upgrade |
|
|
FXOS: Directory /var/tmp Triggering FXOS Fault F0182 due to vdc.log (Excessive Logging,Log Rotation) |
|
|
Set Weight option missing in UI when FTD sensor reverted and re-upgraded |
|
|
Propogate SGT deployed to FTD if copy deviceconfiguration(SGT configuration UI andLINA doesnt match) |
|
|
FMC GUI does not allow saving ECMP configuration when there is a route leak for a VRF |
|
|
Decorator cannot find the realm because there are two realms with same domain name |
|
|
FMC find usage feature not showing all associated access control policies for random objects |
|
|
NAT traps have to be rate-limited |
|
|
FMC/FTD: Policy Deployment Fails For Existing FTDv Deployments on Cloud with VNI interfaces |
|
|
Alert user that FDM is not Supported for FTDv in Openstack if they try to enable it |
|
|
snort "exits normally" in loop every 1 min resulting in complete outage |
|
|
FMC displays VPN tunnel status as unknown even when the tunnels are up |
|
|
Invalid Name Warning Missing from FMC after upgrade and Save greyed out (Configure DAP records through Rest API) |
|
|
Unused objects deletion taking longer time |
|
|
Discrepency in the unused object count between the FMC UI and API results |
|
|
Secure Client Connection Profile Address Pool not Shown |
|
|
Cluster assigning wrong nat for unit, traffic not being forwarded properly back to unit |
|
|
MariaDB import failure that lead to FMC-HA Synchronization Incomplete |
|
|
Use of Named interface in SLA Monitor causing cdFMC migration failure |
|
|
Switch FMC-HA fails: MariaDB replication is not in good state - can not sync |
|
|
FTD running on FPR2k devices, using CMI, has no ARP for 203.0.113.129 |
|
|
FTD deployment fails with error "Snort command failed due to bad config" |
|
|
Memory fragmentation resulted in huge pages unavailable for lina |
|
|
Snort3 Crashinfo not decoding certain lines with "no unwind info found" |
|
|
FMCv300 not consuming any FMCv300 device license |
|
|
fs-daemon hap reset with core generation |
|
|
Secure Client External Browser package Image shown 2 same packages |
|
|
policy_deployment.db does not get updated with the correct anyconnect/secure client version |
|
|
Big chunk of Memory of around 25KB is being allocated on Stack in "eigrp_interface_ioctl" API |
|
|
FMC not using configured proxy for smart licensing |
|
|
Traceback and reload in Thread Name Datapath |
|
|
Primary FTD instance MAC address is not updated correctly in FXOS during failover |
|
|
NAT divert for 8305 on standby not updating post failover causing the Primary, standby FTD to show offline on FMC |
|
|
ACP copy not possible in Firepower Management Center |
|
|
Longevity setup:TPK cluster node is displayed as empty cluster in device mgmt page |
|
|
SNMP walk results in ASCII value for IPSEC Peer instead of an IP address. |
|
|
Unreachable Hosts and URLs of syslog configuration Block Device Management Page Loading |
|
|
MI: Vlan info is not applied at FXOS level when Virtual MAC is configured |
|
|
ASA traceback and reload in freeb_core_local_internal |
|
|
FDM Order of reading nested object group indexing is causing deployment failure |
|
|
Intrusion policy having same name in different Domains causes IPS policy corruption |
|
|
Coverity System SA warnings 2024-09-09, Coverity Defects 922530 922529 922528 922630 921809 921808 |
|
|
S2S VPN tunnel Child SA unsuccessful renegotiation |
|
|
Critical health alerts 'user configuration(FSM.sam.dme.AaaUserEpUpdateUserEp)' on FPR 1100/2100/3100 |
|
|
Frequent traceback after upgrading FTD HA |
|
|
On FMC, Backend server JVM is running out of memory when policies and objects are huge |
|
|
ASA Traceback after upgrade to 9.20.3.7 |
|
|
Send Virtual Tunnel Interface enabled by default on SVTI |
|
|
Tracebacks observed in a cluster member running ASA 9.20.3.4 |
|
|
FCM GUI became inaccessible after upgrading to ASA 9.18.4.22 | FPR 2130 Platform Mode |
|
|
Bandwidth information of a port-channel is not getting updated if an interface member goes down. |
|
|
FDM RA VPN SAML UI does not set port in base-url when custom webvpn port is used |
|
|
“Copy when complete” option not working for SSH Public Shared Key Authentication on FMC |
|
|
Traceback and reload with Thread Name: vtemplate process |
|
|
Traceback and reload during clear bgp * ipv6 unicast involving watchdog |
|
|
Traceback in thread name Lina on configuring arp permit-nonconnected with BVI |
|
|
ASA: IPv6 EIGRP routes learned from other neighbors are missing in updates after failover |
|
|
FMC1600-K9 PDF download failed in deploy tab |
|
|
ASA: floating-conn not closing UDP conns if conn was created without ARP entry for next hop |
|
|
cdFMC - Unable to save network group object |
|
|
ASA/FTD - Traceback and Reload in Threadname IP RIB Update |
|
|
Clearing all non applicable alerts post license registration success |
|
|
Intf Link down (Init, mac-link-down) seen - EtherChannel Membership in Down/Down/Down state after unplug/replug of the cable |
|
|
show blocks old core local can lead to unexpected reload. |
|
|
Smart license UI on cdFMC and FMC showing duplicate license count for Malware , IPS , URLFilter and Apex |
|
|
RA VPN Config Error -- Import PKCS12 operation failed - Deployment Failure |
|
|
Asia/Bangkok timezone option not listed in ASA running on firepower1k |
|
|
Banner motd does not display when configured |
|
|
SSH works in admin context but doesn't work in any user context after changing ssh key-exchange |
|
|
Event-list not deployed when using Enable All Syslog Messages |
|
|
Block S2S and remote access configurations for public cloud cluster |
|
|
FMC UI login fails with "Unable to authorize access." |
|
|
loading an ECDSA certificate into the FMC causes Auth Daemon to crash and reload repeatedly |
|
|
Set limit for the number of glibc arenas in lina to avoid ASA/FTD system overhead memory issues |
|
|
FMC: OSPF NSF-awareness (helper mode) cannot be configured on a standalone FTD |
|
|
Unreachable LDAP/AD referrals may cause delays or timeouts in external authentication on FTD |
|
|
Need the SVC Rx/Tx queue as a configurable option |
|
|
FMC does not remove community list override when this is modified. |
|
|
ISA3000 with ASA Refuses SSH Access If CiscoSSH is Enabled |
|
|
RTSP packets getting stuck in transmit queue leading to 9k blocks exhaustion. |
|
|
FMC Does not throw error with duplicate entries in input while modifying prefix list through API |
|
|
Choosing clause 91 FEC via the FMC sets fec 544 instead of fec 528 on QSFP-100G-CU3M |
|
|
Traceback and Reload caused by Memory corruption with SNMP inspection enabled |
|
|
Realm with greater than 16 directories cannot be deployed in RA-VPN for LDAP |
|
|
Confusing Verdict for Snort Injects - Change From Block to "Replaced"/"Injected" |
|
|
FDM - All IPSec tunnels get reset after changing PFS value for one tunnel |
|
|
User EO revisions accumulate forever, eventually overflowing Pruner's ability to do its job |
|
|
ipv6 ping Vrf name changed after xml processing |
|
|
core corruption still seen with switching to quick core feature |
|
|
snort3 : FMC connection event logs do not show URL in DNS query using TCP |
|
|
ASA clock is out of sync 2 hours when timezone is configured to Europe/Dublin which is GMT. |
|
|
Identity NAT should not throw error due to exceeding threshold if destination only objects expand |
|
|
FP1150 ASA/FTD - Traceback and reload triggered by watchdog timer |
|
|
lucene directory missing from FDM backup |
|
|
High ASA/FTD memory usage due to polling of RA VPN related SNMP OIDs |
|
|
WM-DT- FXOS Critical Faults seen due to PortMgr IPC Communication failure. |
|
|
FMC Not listing the any connect images in RAVPN Wizard and FMT tool |
|
|
Occasionally, 'show chunkstat top-usage' output does not show all entries |
|
|
ASA/FTD may traceback and reload in Thread Name "DATAPATH" |
|
|
FXOS reset and reload due to snmpd service failure |
|
|
Create report option should be hidden from Health Events Page on CDFMC |
|
|
Generate syslog if received CRL is older than cached CRL |
|
|
Generate syslog if received CRL signature validation fails |
|
|
URL getting allowed even with block rule in place. |
|
|
ASA: Traceback and Reload Under Thread Name SSH |
|
|
FTD generates syslog 430002 as VPN Routing without VPN hairpin |
|
|
Policy Deployment Failure Due to Special Characters in AC Policy Rule Names |
|
|
FTD reboot and traceback in DATAPATH due to IPv6 packet processing |
|
|
Error thrown for individual rule hitcount if rule name contains certain special characters |
|
|
Debuggability: FP2100 port-channel interfaces flap after upgrade |
|
|
Tunnel Summary and Topology View in S2S monitoring doesn't display the right status. |
|
|
Dynamic Analysis Status Changed time only changes upon submission of a file for dynamic analysis |
|
|
Use of browser Refresh button on the Captured File Summary page may result in an unexpected warning |
|
|
FTD Upgrade Failure on Script 800_post/020_710_fix_users_and_roles.pl |
|
|
Warning messages from using Analyze button on Captured File Summary page need to be more specific |
|
|
Snort3 trimming packets with invalid sequence number due to bad window size information received |
|
|
VNI source MTU is not IPv6 aware after upgrade if configured prior to upgrade |
|
|
Nitrox Engine (Crypto Accelerator) problem affecting crypto hardware offload on FPR3100/4200 platforms |
|
|
Community lists should not throw an error until the last item in the list is being deleted |
|
|
sfipproxy prometheus configuration is attempted for not supported models and replaces sfipproxy.conf |
|
|
Unable to login to FMC GUI due to HTTP 401 UNAUTHORIZED error |
|
|
Aggressive scale down and scale up of nodes causing the failure |
|
|
Serviceability Enhancement - Make FXOS disk errors more descriptive |
|
|
SNMP walk on FXOS 2.14.1.167 causing warning loop |
|
|
ZIP files are not being transferred when Archive category is selected from File Policy using snort3 |
|
|
Exclude perf monitoring files from device backup |
|
|
ASA/FTD Traceback and reload in timer with stress test on QUIC decryption |
|
|
ASAv reloaded unexpectedly with traceback on Unicorn Proxy Thread |
|
|
Command authorization fallback to Local only works for users with privilege 15. |
|
|
Active HA unit goes into failed state before peer unit gets into a ready state during snort failure |
|
|
SSL trustpoint with 4096 bit RSA keys not allowed by ASA if renewed via CLI |
|
|
Traceback and reload during the deployment after disabling FQDNs. |
|
|
ASA/FTD may traceback and reload in Thread Name 'DATAPATH-3-4280' |
|
|
Enabling debugs with EEM fails |
|
|
The whois lookup command for the FMC GUI does not properly handle errors |
|
|
Detectors sync issue on FMC upgraded to 7.7 |
|
|
Dispatch queue drops have no snapshot or tuple view for dropped flows |
|
|
Snort3 crashed because don't fragment bit was set and it did not treat ipv4 fragments as fragments |
|
|
FDM: De Registration stuck with this error: Licensing task is in progress |
|
|
Buffer calculation for new app_bin missing in the upgrade framework |
|
|
Prune the older files in /ngfw/var/cisco/deploy/pkg/var/cisco/packages |
|
|
FTD - LSP Installation/ Deployment Failure |
|
|
FMC upgrade page shows upgrade failed but the device is upgraded |
|
|
Backup may fail with generic "Backup died unexpectedly" error message |
|
|
IKEv2 Rekeys fail due to fragmentation during the IKE Rekey |
|
|
Importing SFO fails with the error "No UUID Provided" |
|
|
Users from legacy radius server can login to Standby FMC domain when MA is enabled |
|
|
False alert "Terminating long running backup" on FMC due to UI backup timeout error. |
|
|
FXOS allows booting and starting an image installation using a Patch image |
|
|
Snort3 restart on the first deployment post FMC upgrade. |
|
|
ASA/FTD may traceback and reload in Thread Name 'lina_exec_startup_thread' |
|
|
FMC removes prefix-list overides used for BGP and installs defaults values by itself. |
|
|
Unable to rejoin data node in cluster after re-enabling mac-address auto in multi-context mode |
|
|
FTD TS is collecting duplicated data |
|
|
Better handling of invalid/bad data in fleet upgrade workflow. |
|
|
process_stderr.log: Could not open link aggregation log file '/ngfw/var/log/link_aggregation.log' |
|
|
Port scan alerts not getting generated for custom configuration |
|
|
Reduce TS package size |
|
|
FTD sending "0.0.0.0" NAS-IP-Address attribute when authenticating/authorizing using Radius |
|
|
debug packet-condition does not work as expected |
|
|
9K block depletion causing slowdown of all traffic through firewall |
|
|
Suddenly customer lost SSH access to the ASA |
|
|
Empty snapshot being sent when when auth-daemon restarts causing user logout |
|
|
Critical health alerts for data interface on standby node - HA setup |
|
|
DNS and default gateway are removed on FTD managed through data interface - DNS |
|
|
auth-daemon process restarts due to race condition |
|
|
Deployment failure due to invalid AnyConnect Images and Secure Client Profile references |
|
|
REST Api allows to create a realm without a directory configuration |
|
|
Enhance Backup Status Notifications for Unified Backup Failures on FMC |
|
|
Upgrade failure after RMA due to Sensor table having incorrect serial number |
|
|
Unexpected SFDataCorrelator exit after deployment to managed devices following VDB install on FMC |
|
|
Default Route Changes from Management0 to Management1 After Reload or Upgrade on FPR 4200 Series |
|
|
Management1 Gateway Configuration Should Be Optional on FPR 4200 Series |
|
|
FMC Site-to-Site Monitoring Dashboard is not working at all |
|
|
Unit taking ~13 secs to become active |
|
|
FMC remote storage test sometimes fails when configured to a server running Solar Winds SCP/SFTP |
|
|
Virtual ASA Traceback and Reload Caused by Disk Access Issues with NFS Enabled |
|
|
AC policy with Network Group Override object causes deployment failure/rules missing |
|
|
TLS.- Outlook only supports TLS 1.2 and not 1.3- FMC uses TLS 1.3 by default |
|
|
LSP upload/download + auto-deploy is failing |
|
|
Disable Reverse Path Filter for Dual Management Interfaces on FPR 4200 Series |
|
|
Active FMC - False alerts of FMC HA in degraded sync state |
|
|
FMC Alert: Discover Health Module Compilation Error |
|
|
CIMC Password length restricted to 16 characters with LOM enabled |
|
|
FMC: Deployment takes longer than expected when removing SNMP hosts from Platform Settings |
|
|
FTD upgrade allowed with dirty policy after FMC upgrade |
|
|
Random QOS policies are getting negatted and added with subsequent deployment |
|
|
First cycle of FMC HA periodic sync may fail after resuming sync following FMC software upgrade |
|
|
Remote storage server password showing in plaintext in httpsd_error_log |
|
|
AMP related health alert during upgrade and typo in the alert message |
|
|
Enhance Debugging for add/update/withdraw of routes with neighbors |
|
|
Deployment due to system upgrade is failing at PREPARE phase in FDM-HA |
|
|
Serviceability Enhancement - New 'show bgp internal' command for advanced debugging |
|
|
ASA/FTD traceback and reload in vaccess_nameif_action thread |
|
|
FMC: Media type displayed on the FMC's FCM is not matching CLI after swapping sfps |
|
|
Remote backup generated successfully but configuration database backup is empty |
|
|
Smart license UI showing variable performance tier when stand by FMC is made active |
|
|
cdFMC does not show more than 25 realms in the GUI |
|
|
sftunnel and sfipproxy configuration files updates are not atomic |
|
|
Getting " Realm is disabled, enable it on the Realms page " while adding dynamic attributes |
|
|
Traceback & Reload in thread named: DATAPATH-1-23988 during low memory condition |
|
|
SSL Debug Logs Persist After Debug Reset |
|
|
show tech-support fprm detail command is getting stuck for longer duration |
|
|
Snort3 traceback and deployment failure with VDB upgrade |
|
|
Memory leak leading to split brain |
|
|
ENH: Include SystemID in "show system detail" in techsupport file |
|
|
Module show tech generation fails with external authentication |
|
|
Firepower hits route limit due to ASP table resource exhaustion affecting traffic forwarding |
|
|
Ensure the watchdog triggers even if a single snort3 thread becomes unresponsive. |
|
|
Counter from IKEV2 stats does not match the number of tunnels in VPN-Sessiondb |
|
|
SecGW: Data node fails to join the cluster with cluster_ccp_make_rpc_call failed to clnt_call error |
|
|
Port-channel member interface flap renders it as an inactive member |
|
|
sfipproxy may not restart and fail services like User Identities when enable file is not detected |
|
|
Disabling OSPFv3 on FMC does not clear passive interface and area config from FTD interfaces |
|
|
FMC IPsec SA remaining key lifetime incorrect conversion of seconds to hh:mm:ss |
|
|
Cluster node got deleted partially and devices have become Standalone on FMC UI |
|
|
ASA may traceback and reload in Thread Name 'fover_parse' |
|
|
syslog-ng may not immediately restart on FTD as expected upon changing FTD host name |
|
|
Installation of Hotfix may fail at 800_post/998_expire_ac_policy.pl on the standby FMC |
|
|
Deployment cannot be initiated due to preview diff report generation request in progress |
|
|
Fleet copy package fails: Copies completed but failed to be acknowledged by device(s): 1. |
|
|
FMC - Health Monitor shows 'No Data Available' due to too many open files |
|
|
Logging recipient-address not overriding the logging mail message severity levels |
|
|
After upgrade from newer lower MR to Old Higher MR seeing health module compilation error |
|
|
DNS and default gateway are removed on FTD managed through data interface |
|
|
Warwick Avenue: LLDP neighbours are not discovered if MGMT 1/2 interface is down |
|
|
Decryption policy failed to migrate to cdFMC from on-prem FMC. |
|
|
/mnt/disk0/log folder duplicated on troubleshooting package |
|
|
Generic or irrelevant error for remote storage device test/save failures |
|
|
Error after logging out from FMC UI using SSO with PingId |
|
|
ASA FTD traceback in Checkheaps process after enabling "controller monitor internal-interfaces free-blocks 100" command |
|
|
FTD health metrics show "No data available" on the FMC |
|
|
Upgrading a 7.0.x sensor to 7.0.7 when managed by an FMC via hostname results in errors |
|
|
Serviceability enhancement for "system support trace" capabilities |
|
|
Traffic failure due to 9344 blocks leak |
|
|
FMC Rest API returns only the first 1000 network object entries |
|
|
Snort3 Traceback due to watchdog during appid NAVL instantiation |
|
|
'${dsk_a} missing or inoperable. Rebooting Blade.' error does not specify missing or inoperable disk |
|
|
Overrides not working on chained/inherited custom IPS policies |
|
|
[Cluster] CPU Utilization of 100% when NAT Pool exhaustion happens in a context. |
|
|
FTD: Large Delay in packets being inspected by snort |
|
|
Add "built" and "teardown" messages for the GRE | IPinIP connections to the Lina syslog |
|
|
FTD does not synchronize via NTP from Secondary Management Center in HA when the Primary is down |
|
|
DNS doctoring not working correctly if the doctoring rule is of type dynamic and has any interface |
|
|
After renewal FMC CA, the certificate cannot be used for ArcSight integration |
|
|
Logical App Stuck in 'Start Failed' Due to checkSystemCPUs Failure |
|
|
Failover and state link not accepting valid subnet mask |
|
|
Default Pass action for rules in Snort 3 local rule groups may cause blank error in IPS policies |
|
|
mix of major versions between FMC and FTD causes per-core CPU use health module to not work on FTD |
|
|
FMC/FDM Client side certificate used to communicate to Talos did not auto-renew correctly |
|
|
CPU core numbers not specified in results from operational/metrics FMC REST API endpoint |
|
|
FPR9K-SM-56 Cluster - FTD Stuck in an application install loop & error 'pooled address is unknown' |
|
|
FTD HA | Same MAC for port-channels causing network outage. |
|
|
Deployment to FTD Fails at 5% due to corruption with interface object |
|
|
Network Outage when Primary FTD Instance is Disabled from FCM |
|
|
snmp_logging_thread is utilizing high CPU in control plane |
|
|
FMC health policy and Default Health Policy do not have correct moduleList |
|
|
FPR9K-SM-56 Cluster Node APP_SYNC timeout twice before joining "6" member inter-chassis cluster |
|
|
Refresh Icon on Inventory Details Fails to Update Chassis Information for All Models |
|
|
/objects/fqdn filter paramaters not working |
|
|
FPR1010 Ethernet1/1 trunk port is not passing Vlan traffic after a reload |
|
|
The NAS-IP-Address attribute is missing from the Access-Request in FMC |
|
|
Handle cases where Vault is not running during task execution and add health Alert |
|
|
Captured file status is not updated if threat score is cached on FTDs |
|
|
Bulk Edit Rules - Security Zone Search does not yield all zones if zone count is more than 1000 |
|
|
Deployment Failure in Hub and Spoke VTI Topology with DHCP Configured VPN Interfaces |
|
|
BFD flap due to ASA not processing incoming BFD packets after unrelated BFD peers go down |
|
|
SNMP polling to chassis is unsuccessful with FTD Multi-instance in HA used as SNMP agent |
|
|
SNMP configuration is not applied consistently across same FTDs type and version |
|
|
Deployment failure due to rsync |
|
|
3100 Marvell 4.3.14 CPSS patch for the interface mac stuck issue seen with peer switch reloads |
|
|
TLS handshake fails with reverse SSL flow and TSID (TLS Server Identity) enabled |
|
|
ASA/FTD traceback and reload with SNMP Notify Thread seen on 3110 |
|
|
FMC getting health alert - cgroup_monitor exited 5 time(s) |
|
|
Passive Agent core containers like BEE does not come up beyond 3 crashes. |
|
|
Certain special characters or spaces in RADIUS user passwords cause login failure in FMC |
|
|
Portscan event in FMC displays incorrect source/destination when set to 'low' setting |
|
|
Object search failing due to BB invalid data |
|
|
Deploy failure seen when we use same vlan id in vlan intf and sub intf |
|
|
Traceback in thread name DATAPATH when a unit is re-joining the cluster |
|
|
deployment slowness seen when huge number of policies are present |
|
|
Post-Failover FQDN Resolution Deferred Until Next DNS Poll Interval |
|
|
Post reposition or move operation fails then if user saves, it would lead to loss of rules & may cause an outage |
|
|
Cryptochecksum changed after reloading. |
|
|
BFD packets are not dropped for single-hop BFD sessions received via alternate path |
|
|
Saving changes under Policy > Alerts > Intrusion Emails in FMC GUI multiple times removes old changes |
|
|
'configure network management-data-interface' allows to configure same IP on data and mgmt interface |
|
|
Local user details not replicated to data nodes in a cluster setup. |
|
|
ASDM: Displays Error of Keypair already exists when adding an identity certificate. |
|
|
Difference in RSA key length at multiple spots in FXOS |
|
|
L3 Clustering where BGP immediately comes up while DATA node is still in bulk sync |
|
|
Deployment failure not updated on databases of data node |
|
|
FMC page may get stuck in loading state while trying to fetch BGP configuration |
|
|
Unidirectional communication over ccl leading to split-cluster. |
|
|
FTD Hub-and-Spoke VPN Topology – Backup VTI Fails When DHCP is Used for External IP |
|
|
SMB remote FMC backups are failing due to relam sync |
|
|
FTD Dashboard queries only primary device for FTD HA |
|
|
Boot-Time warning if CPU core count is below minimum requirement |
|
|
ASA/FTD: Primary standby unit becomes Active after reload in HA set up |
|
|
backout change preventing enabling clustering in FIPS mode |
|
|
ASA/FTD traceback and reload triggered by the Smart Call Home process in sch_dispatch_to_url. |
|
|
If command replication fails to any nodes in cluster, send kick the node out from cluster to fmc |
|
|
Policy deploy would not write entries when referenced object is missing |
|
|
Command replication failure to cluster nodes on command commit noconfirm revert-save after access-list, additional debugs |
|
|
FMC Custom widget to display host count per sensor shows incorrect sensor name |
|
|
"Error during policy validation An internal error is preventing the system... "due to stale sensor ref in security zones |
|
|
ASA: MAC address of the port-channel interface changes leading to ping failure |
|
|
SSH Login Fails Across All Contexts After Removing SSH Configuration from One Context or Deleting a Context |
|
|
Missing RADIUS accounting response messages may result in delays or failures of connectivity from chassis to instances |
|
|
fover_trace.log not rotating and growing to a massive size |
|
|
FPR 4125 Multi instance: High Snort and System Core CPU Usage (100%) Triggering FMC Critical Alerts |
|
|
FMC Unable to Download User Groups from AD Realm via LDAP |
|
|
ASAv restarts unexpectedly |
|
|
ASA: asacli Processes Not Terminated When SSH Sessions Are Closed |
|
|
cdFMC Not Displaying Interfaces and Security Zones When HA Secondary Device Is Active |
|
|
FMC Displays SSE Enrollment Failure Alarm Despite No Active Integration with SecureX |
|
|
Duplicate VTI cause VPN Flaps |
|
|
FTD Cluster: Incorrect log when snort engine restart times out |
|
|
FTD: SGT Inline tag stripped from SIP packets |
|
|
FP4100/9300 Fatal error: Incomplete chain observed before watchdogs with reset code 0x0040 |
|
|
LINA stays inactive without reloading after traceback on non-CP thread |
|
|
Users with "Modify Threat Configuration" permission are not able to modify Intrusion/File Policies within the Access Control Policy (ACP) rules |
|
|
Unified Event Viewer does not work with certain filters |
|
|
Secondary Address should only be configurable for FMC-managed FTDs when using data interfaces for management |
|
|
Unable to Edit or Break FTD-HA via FMC GUI because of UI lock issues during create |
|
|
The total disk keep on increasing on the disk status wizard on the Health Monitor page. |
|
|
FTD MI: SNMP polling fails to work after upgrade |
|
|
Excessive number of AD users in FTD External Authentication could lead to deployment failure when disabled. |
|
|
Error Encountered While Disabling the 'Call-Home Reporting Anonymous' Option in Call-Home Configuration |
|
|
Devices show offline due to "Appliance unreachable" due to HMS deadlock inserting to DB |
|
|
FTD Intermittent Syslog Alert: mcelog daemon is not running. Restarting the daemon. |
|
|
ASA/FTD traceback and reload in function mp_percore |
|
|
FPR failover split brain when upgrade primary/standby device's FXOS version |
|
|
Snort2 crashes in loop after FMC upgrade |
|
|
Subsequent DNS packets are dropped in a single flow if one domain hits the custom DNS SI block list |
|
|
ASA traceback and reload |
|
|
high CPU usage after ASA upgrade from 9.20.3.9 to 9.20.3.16 running on Hyper-V |
|
|
SFF_SFP_10G_25G_CSR_S modules from Finisar ports bouncing when connected. |
|
|
FMC Restore of remote Unified backup fails due to no space left on the device |
|
|
Error 500: Internal Server Error in FMC when generating report for global domain intrusion policy used in child domain ACP |
|
|
ASA: tls-proxy maximum-session command error |
|
|
ESP packets encapsulating subsequent fragments are dropped with ASP unexpected-packet drop reason |
|
|
SSL error causing connection to Cisco Smart Software Manager (CSSM) to terminate |
|
|
ASA/FTD: the ssl trust-point command deleted after a reload |
|
|
User Creation Fails with RADIUS Dynamic Provisioning Enabled on Firepower device. |
|
|
FMC GUI Inaccessibility and blank due to 'Malformed JSON String' Exception |
|
|
Deployment is mandatory after FMC upgrade condition should be included in Upgrade code |
|
|
FMC UI breaks when configuring Client-side interface settings for DHCP Relay |
|
|
Collecting "show tech-support fprm" results into core for tar itself |
|
|
No log file present for troubleshoot generation, if there is any issue with TS generation |
|
|
Wrong URL incorrectly displayed for file upload with Japanese text in file path for client-less VPN |
|
|
Tmatch memory is mostly consumed by ARP-DP. |
|
|
The Firepower bandwidth_analyzer.pl script does not perform proper input validation for the '--size' option |
|
|
Unable to change few IPS rule actions after upgrading from snort2 to snort3 |
|
|
FMC Audit tcp-tls syslog is truncated or incorrectly formatted |
|
|
Negative value displayed for buffer drops when using " show cluster info load-monitor details" |
|
|
Tunnel Status shows "No Active Data" when spoke behind NAT on S2S Monitoring UI |
|
|
ASA crashinfo files not generated on FP4200 devices |
|
|
Syslog format is not properly printed when EMBLEM format is enabled at least in one syslog host |
|
|
ADI cores reading corrupt SXP file |
|
|
FP9300/4100 may traceback & reload due to a "Kernel Panic" |
|
|
Multiple mail drops and enq failures are seen while traffic is going through the box. |
|
|
depoyment failure reason and transcript to be updated on FMC |
|
|
Policy deploy failing on FTD when trying to remove Umbrella DNS Configuration |
|
|
wpk - 1gsx link remains up on wpk but on switch side it shows as not connected |
|
|
Error while downloading lsp from support site because VaultApp could not unseal Vault on FMC |
|
|
FDM stuck deployment task in Queued state |
|
|
An ICMP not reachable storm might cause high CPU on a two units FTD cluster |
|
|
Secure firewall posture image is not available in the ASA device backup when generated from ASDM |
|
|
CPU usage by "WebVPN Timer Process" on standby ASA device |
|
|
cdFMC returns 403 forbidden error while configuring webhook alerts |
|
|
FMC deployment hungs and fail due to "NGFW_UPGRADE is missing in map" |
|
|
WA HA: Error while fetching metadata for FTD HA. |
|
|
Case differences in SAML SSO usernames cause login loop |
|
|
FMC reporting IPv6 non overlapped host object-group as fully overlapped object-group |
|
|
Multiple consumers try to bind to the same ZeroMQ socket |
|
|
Deploy failure when Indexing is not working |
|
|
Error : Msglyr::ZMQWrapper::registerSender() : Failed to bind ZeroMQ Socket |
|
|
Deployment failure when selecting ECMP zone member interface in ZTNA policy |
|
|
SAML IdP entityID increase from capped 128 character maximum |
|
|
dmesg and kern.log file flooded with Tx Queue=0 logs |
|
|
IKEv2-EAP Authentication Fails with Windows and MacOS Native VPN Clients |
|
|
Clarify the working of Fallthrough to Interface PAT (Destination Interface) as it is not working as expected |
|
|
The estreamer debug command is not producing the expected output |
|
|
"CSRF Token Mismatch" error seen when users click logout from Clientless VPN page |
|
|
Internal error is seen when editing the rule with IPV6 contents |
|
|
The chassis serial number is empty post registration in FMC |
|
|
Clean-up of temporary tar file is not happening when copy to remote storage fails during backup. |
|
|
If a user_ip_map.snapshot exists with an low timestamp value, snapshots are created frequently |
|
|
Traffic drops post deployment when secondary skips app sync and become active immediately after bootstrap config apply |
|
|
ASA Memory leak while processing large CRLs. |
|
|
LDAP users in ACP always show realm out of sync. |
|
|
Capture the reason of reboot in FTD logs |
|
|
FTD Active Authentication hostname value not included in cp_redirect_params.conf file |
|
|
ASA Core file generated is corrupted |
|
|
ASA Clock reverts to UTC after device reload |
|
|
ASA/FTD: ASP drop capture for 'invalid-ip-length' or 'sp-security-failed' does not work with match criteria |
|
|
Customer DU CONSULT, NPS 6 - ACP search toggle for exact IP or Port match |
|
|
Memory leak in SSL crypto causing high Lina memory usage on lower-end devices |
|
|
Opening, imported policy says internal error. |
|
|
HA state should not transition from ColdStandby to Active |
|
|
FMC Auto Deployment Task fails to run repeatedly |
|
|
URL filtering download failure - talosAgent keeps exiting on FMC |
|
|
Cluster: Multi-blade chassis not transmitting broadcast traffic outbound to specific vlan |
|
|
SSL - Issues with DND a particular site after FTD upgrade on Chrome and Edge post upgrade |
|
|
FMC - AC policy UI becomes unresponsive if the user edits ACP while there are more than 1K ACPs on FMC |
|
|
TCP RST Packets Fail to Match Configured Geolocation-Based Rules |
|
|
Data Node Deregisters from With No Clear Error Message on vFMC in AWS When Deploying Stack Using Private IP's |
|
|
FP1140 Critical FXOS fault alerts (F1000413) after upgrade |
|
|
Prolonged delays in firewall restart/reboot completion |
|
|
Restoring .tgz context file causes allocated interfaces to be removed from 'system' configuration |
|
|
Need to have deploy Warning for IKEv2 Policy with same Priority Conflict in FTD VPN Configurations on FTD |
|
|
High disk usage due to snort-unified.log |
|
|
FTD - SNMP Walk of FXOS FTD OID Tree Returns Empty or Times Out |
|
|
SFDataCorrelator_user_id_mismatch.log overconsumption of disk |
|
|
Adding interface taking more than 30 sec with loading security zones |
|
|
FMC Dynamic Objects Limited to 1000 |
|
|
LINA traceback Observed on FTDv Firewalls Deployed in Azure: snp_vxlan_encap_and_send_to_remote_peer |
|
|
FMC Overview Connection Summary Shows No Data by Responder IP |
|
|
Threat/AMP Upgrade tasks are being created soon after HF installation completed |
|
|
WA: Traceback and reload due to lock contention on the tmatch table during deployment with large snmp config |
|
|
Missing Security Zones in zones.conf Affecting ngfw.rules Functionality |
|
|
If failover IPSEC PSK is 78 characters or greater HA breaks with "Could not set failover ipsec pre-shared-key" |
|
|
Inventory details on FMC GUI shows the incorrect compliance mode |
|
|
Files missing from FTD troubleshoot file |
|
|
FPR42xx - SNMP poll reports incorrect FanTray Status at Down while actually operational |
|
|
FMC dashboard dynamic analysis over time is shown as "No Data" |
|
|
Stop generating health alerts for transient high CPU utilization |
|
|
Issue with interface status visibility in Firepower Chassis Manager 4225 managed by FMC |
|
|
Memory Leak observed on FP2110 running ASA due to monitoring interface configured in HA |
|
|
FP3105 Traceback and Reload after changing the speed on Ethernet interface |
|
|
Snort may drop SCTP packets and block SCTP connections |
|
|
Schema Validation Error Encountered While Editing AnyConnect/Secure Client Profiles |
|
|
The syslog server called fluentbit can't recognize the fox syslog format and print it |
|
|
3100/4200: 1G Management interface flapping after upgrade |
|
|
FMC generate_certs.pl script fails to regenerate CA Certificate |
|
|
Audit Logs Display Repeated Session Expiration Entries Even When the System is Idle |
|
|
RAVPN Geolocation: Deployment failing by enabling all or specific countries in service access object |
|
|
Traceback and Reload while two processes attempt to free a TD subnet structure |
|
|
Misleading "failover reset" log printed on console when reload triggered by HA. |
|
|
management-data-interface commands fail with "Enable of interface failed" error due to case-sensitive interface name |
|
|
3RU MI instances offline after baseline/creation |
|
|
FTD: Injected/Trimmed packets dropped by LINA due to invalid-ip-length |
|
|
FDM Intrusion Events Not Displayed When Browser Language Is Set to Japanese |
|
|
S2S VPN is not recovering after IPSEC-Rekey event |
|
|
FTD may drop traffic in the Azure cloud at mlx5 driver level. |
|
|
Security module reboot triggered by a CIMC reset. |
|
|
Policy Deployment tasks should not be stuck indefinitely |
|
|
ASA: Traceback and reload on threat detection, interfaces unstable after that |
|
|
Deployment fails deployment with "Deployment failed due to failure in retrieving running configuration information from device." |
|
|
Duplicate messages during deployment to be discarded by CD to avoid further deployment failures |
|
|
Flash Device error: Azure FMC |
|
|
Snort3 blocking ESMTP traffic intermittently and trigger IPS signatures: 124:1:2 |
|
|
ASA/FTD - Assert triggered during FP_PUNT replace (aaa account match) |
|
|
Traceback and reload after editing SNMP config, with tmatch |
|
|
Failed to convert snort 2 custom rules. Refer /var/sf/htdocs/ips/snort.rej for more details. |
|
|
Local FTD backups are failing due to a lack of disk space on /tmp. |
|
|
Long running AQ task got killed after timeout on FMC but corresponding backup task on FTD is still running |
|
|
Backup Timeout is not sufficient when FTD backups are huge and low bandwidth |
|
|
FTD backups sizes are huge like close to GB and above |
|
|
Firepower 9300 - DNM-2X100G Interfaces not passing traffic post upgrade to FXOS 2.17.0.518 |
|
|
Errors on all interface of FPR1010 | line protocol is down ( not associated with supervisor ) |
|
|
FP3100/4200 rebooting after generating crypto_archive with error on console "KC ILK issue detected" |
|
|
Post FTD HA device deletion, RAVPN VPN references were still present causing deploy failures for existing ones |
|
|
OSPF: High CPU, Route flaps, Lina Traceback and Reload in High Availability Setup. |
|
|
Secondary FMC-HA Peer Exclusion list not taking effect for Network Discovery |
|
|
Rule action 'Disabled' of rule 1:23858 in Secure Firewall Management Center does not align with snort.lua in Firepower |
|
|
Need to remove compatibility popup added by CSCut04399 on ASDM |
|
|
Dynamic Attributes Connector Status shows One or more services are unhealthy |
|
|
Idle SSH sessions persist beyond the configured timeout without graceful termination by Fin flag |
|
|
Multicast and broadcast packets do not reach all multi-instance firewalls via shared interface on 3100/4200 |
|
|
Intrusion Event Packet Data via syslog/estreamer show no packet data for large packets |
|
|
SmartLicensing should accept certain special characters |
|
|
ASA SNMP Response Issue - Responses Sent Only for Odd OIDs, Not for Even |
|
|
debug menu tls-offload option <> to be provided to resolve slow download speed using curl to download large file with SSL Decrypt Resign Policy |
|
|
Lina Traceback and Reload after enabling 'TLS Server Identity Discovery' |
|
|
Unable to use the plus sign in the email-id for the identity when configuring an S2S VPN |
|
|
Deployment failure soon after forming FTD HA |
|
|
FTD: Packets Dropped due to tcp-seq-past-win due to delayed packet through Snort |
|
|
ASAv deploy failed - console stuck at continuous |
|
|
Multiple System Configurations Missing from FMC GUI Post-Upgrade |
|
|
ASA/FTD in HA, snmptranslate process during the boot-up causing High CPU and IPC timeouts, causing split-brain. |
|
|
Update EventHandler SSE consumer when upgrading to 7.7.10 and 10.0.0 |
|
|
FTD packer-tracer showing remark rule id in access-list for a rule not getting hit |
|
|
FTD Traceback while executing 'asp load-balance per-packet' |
|
|
SSH login to FTD management IP address lands in FXOS shell instead of FTD CLISH due to missing /mnt/boot/application/*.def file |
|
|
Multicast and unicast packets do not reach the correct instance for random subinterfaces |
|
|
FTD 3130 HA Lina tracebacks at ikev2_bin2hex_str |
|
|
FMC Upgrade stalls Indefinitely at 999_update_onpremfmc_diskcache.sh |
|
|
FMC 7.6 NAT Source and IP Not Populating within Unified Event Viewer |
|
|
7.6 - Firepower 3100 series - Upgrading an HA pair from a version without the fix for CSCwo00444 to 7.6 causes one firewall to go into a traceback/reload loop |
|
|
Unable to edit Dynamic Analysis Connection cloud settings when FMC cannot connect to the US cloud |
|
|
FMC uses old DNS server for resolution despite correct configuration |
|
|
FTD is not sending a reset packet when the incoming traffic hits "block with reset" rule |
|
|
FTD upgrade failed due to bundle image existence verification failure |
|
|
FMC does not allow to use IP address with 0 value in last octet as gateway while configuring static route for a device. Error: Enter valid IPv4 host value |
|
|
FTD does not generate any events for the Platform Faults health module if no platform faults are present |
|
|
FPR 4200: HA link arp packets getting dropped, internal uplink linkChange counters incrementing |
|
|
FMC ACP Top User Deleted When Deleting Users With Legacy UI |
|
|
Password Expiry Age does not reset after Password Change |
|
|
ASDM: Using the Secure Client VPN Wizard results in an incomplete configuration |
|
|
Though disabled rules exist , are shown as 0 for Snort3 rule recommendations |
|
|
show asp rule-engine issues with complete and run time |
|
|
Running "show crashinfo" appends show tech-support output with crashinfo (lina crash) |
|
|
non-SSL traffic wrongly classified as SSLv2 causing drops with TSID enabled |
|
|
SNMP traps are not sent to one of multiple SNMP servers, in certain conditions |
|
|
WPK: EPM firmware failing to upgrade after reboot |
|
|
FMC - Deployment Fails with "Deployment failed due to timeout during configuration generation" |
|
|
ASA : Performance and high CPU usage seen on Hyper-V |
|
|
IKEv1 L2Lvpn fails in phase 2 with "Rejecting IPsec tunnel: no matching crypto map entry" after upgrade |
|
|
HA Primary/Active unit goes to disabled state as "HA state progression failed due to app sync timeout" in build 10.0.0-196 |
|
|
ASDM fails to connect via ipv6 due to https hostname wrong error |
|
|
FTD: Instance stuck in Boot Loop |
|
|
IPv6 function is stalled, link-local address marked [DUPLICATE] and IPv6 traffic stopped after failover due to split-brain |
|
|
502 Proxy Error when regenerating certificate in ISE Quick Configuration tab |
|
|
Clustering : SNMP traffic drop due to cluster redirect offload |
|
|
SRU Upgrade Fails Due to Leaked Activity IDs from ClusterPostUpgradeHandler |
|
|
Remote Access Monitoring doesn't show client IP correctly. |
|
|
Send Email when complete emails not working with advanced deployment |
|
|
Intermittent Blank Screen When Loading Access Control Policy in New UI |
|
|
tunnel protection ipsec policy feature not working on backup VTI tunnel |
|
|
Possible unregistration when deploying during HA Switchover |
|
|
FTD MI: SNMP polling fails to work after the upgrade |
|
|
Not probing for http Opportunistic TLS |
|
|
Packet Captures show misleading information when blocked due to TCP server unavailable. |
|
|
FP4225: Interface with SFP - 10/25G_LR_S (or CSR_S) is not coming up after reboot of peer side. |
|
|
Number of sessions in cache for Tomcat are set incorrectly |
|
|
Firepower: SSH access lost after timezone change in platform mode |
|
|
FMC UI displays upgrade failure despite successful firewall upgrade |
|
|
ASDM Parsing Failure on Two Contexts |
|
|
WA MI: Two apps went to Not Responding state with reason: Error in App Instance ftd. sma reported fault: Instance xxx is disabled due to restart loop. Please consider reinstalling this app-instance. |
|
|
ASA client IP missing from TACACS+ authorization request in SSH |
|
|
Http inspector support for OPPORTUNISTIC_TLS |
|
|
Reboots on FP2130 due to missing heimdall PID |
|
|
Unable to upload Secure Firewall Posture image file with a size over 200MB |
|
|
"no http server basic-auth-client ASDM" allows ASDM connections to ASA. |
|
|
Remove Object Overlaps can remove unrelated objects |
|
|
DNS-GUARD is not capable to be de-activated on FTD Devices |
|
|
MonetDB may fail to start on FMC if maximum parallel/concurrent logins per CLI user is set to 1 |
|
|
Interfaces are coming up when the Firepower is shutting down |
|
|
FlexConfig migration may cause sudden logout from FMC GUI session |
|
|
Policy deployment fails when inline-set is configured on FTD HA |
|
|
'Access token invalid' is prompted, if a stress test is made on the ACP |
|
|
Low RAM allocation on ASAv can trigger unexpected behavior in 'asdm image' command |
|
|
Flexconfig policy deletion left the stale references |
|
|
cdFMC: All Device Deploy Validations were failing post deletion of Flexconfig for one device |
|
|
Cannot delete interface objects with names over 30 characters. |
|
|
Cleanup of perf_monitor files per instance per day |
|
|
FPR4215 "Not supported" alarm occurred, when insert the SFPs |
|
|
FDM: UI gets stuck on upgrade progress at 9% when upgrade fails attempting to install an already installed hotfix |
|
|
Traceback in HA stby node while snmpwalk on natAddrMapTable |
|
|
FMC does not accept underscore characters for remote storage hostname settings |
|
|
ASA/FTD: Traceback in thread name CP Processing due to DCERPC inspection |
|
|
Database synchronization should auto-resume post network/checksum issues |
|
|
EventHandler wastes CPU re-scanning files that contain no requested events |
|
|
Connection blocking active although "logging permit-hostdown' is set |
|
|
Summary Dashboard widgets do not wrap or truncate text properly |
|
|
Timeout values not honored after "sftunnel_change_max_conn_check.pl" changes |
|
|
Sftunnel TLS13 connection goes down after upgrade when two interfaces configured with same IP on FMC GUI |
|
|
Standby FMC Fails to Sync ids_event_class_map Table, Resulting in Misclassified Intrusion Events |
|
|
Both the units in HA changed the encryption algorithm simultaneously |
|
|
FMC API is reporting Windows for all AnyConnect images while querying RA VPN policies |
|
|
add context for cmd-invalid-encap asp-drop type in the "show asp drop" command usage |
|
|
Block 80 depletion ssl_decrypt_cb |
|
|
4200 interface image in FMC does not match interface order in device |
|
|
FPR HA ESP sequence number discrepancy when standby changes to Active resulting in Anti-replay drops |
|
|
Use of FMC GUI features via user role escalation may cause user to lose all permissions during GUI session |
|
|
FTD port status not reflecting properly on FMC. |
|
|
Intermittent deployment stuck "in progress" for few devices |
|
|
Deployment changed performance profile, unable to retrieve running configuration |
|
|
Traceback seen while FQDN list expands more than 200 entries for a resolved ip |
|
|
FTDv Dropped Packets After NAT64 With Reason "failed-to-setup-pdts-flow-param" |
|
|
Device doesn't boot and gets stuck after a successful upgrade |
|
|
SRU-triggered policy deployments occurred following initial/standby FMC during FMC HA & standalone upgrades |
|
|
Slow UI and inability to check disk usage on FMC due to NFS configuration |
|
|
File policy stops working due to SMB tcp conn terminated after 1hr for unknown reason despite not idle |
|
|
Anyconnect users incorrectly get the prompts, based on the previous tunnel-group |
|
|
ASA: Traceback and reload after saving asdm image |
|
|
Show crypto accelerator shows max crypto throughput is 6 Gbps For 3K & 225Mbps for FTDv |
|
|
Empty Dynamic Attribute IP mappings pushed to FTD from FMC Secondary Unit |
|
|
Deleting a domain using domain_manager --deleteDomain <domain_uuid> on FMC CLI brings down the estreamer service |
|
|
SNMP OID Polling for Chassis temperature not giving response |
|
|
Secure Client SAML - External Browser May Prompt for a Certificate when using IKEv2-IPsec and Certificate Mapping |
|
|
FTD may generate a large number of "ssl-certs-unified" files. |
|
|
TLS audit syslog configuration and certificates not replicating to secondary FMC in HA deployment |
|
|
Continuous logs_archive.asa-interface-idb.log getting generated on ASA |
|
|
FMC GUI slow time to load web pages post upgrade to 7.6.x |
|
|
FMC may not complete Cisco Security Cloud integration when using on-prem Smart Software Manager for smart licensing |
|
|
FTD HA Upgrade Failed on Secondary Unit Due to HA Being in a Failed State From FMC's Perspective |
|
|
ASA/FTD may traceback and reload citing Thread Name 'lina' as the faulting thread. |
|
|
Dynamic Offloaded Flows Interrupted midstream |
|
|
FMC is returning status code 400s of GET request for Get Device Data |
|
|
Disabled certificate is easily accessible and the sanitisation alone is not fool-proof |
|
|
cdFMC 7.7 Fails to Display Health Data for specific FTD's |
|
|
Intermittent drop of self-originated ICMP TTL exceeded messages with reason "Unable to obtain connection lock (connection-lock)" |
|
|
FTD/ASA may traceback and reload |
|
|
FMC/FTD: Policy Deployment failure after disabling NVE Interface config in VTEP Tab of FTD Cluster |
|
|
FTD Policy deployment reported as failed incorrectly on FMC when communications disrupted |
|
|
Lina traceback due to the incorrect option being received in the packet. |
|
|
Secure client tunnel group authentication is affected when using SDI protocol |
|
|
Interlaken (ILK) link between the Nitrox and KC2 failure, causing traffic backpressure / traffic outage |
|
|
Device upgrade using direct downloads from support site doesn't work correctly when FMC is behind a proxy |
|
|
ASA/FTD: Wrong value shown for X509_STORE_CTX in 'show ssl objects' |
|
|
S2S VPN status for Topology with Extranet shows inconsistence at times. This is because when the tunnel status is received from the device bidirectional update should happen |
|
|
RTSP Flows are dropped with drop reason "First TCP packet not SYN" |
|
|
GUI: File upload shows generic 'Invalid file size' instead of actionable message with actual and maximum allowed sizes |
|
|
ASA/FTD - Traceback and Reload in Threadname DATAPATH |
|
|
Flow TRUSTed even before EVE gets initial packets |
|
|
Rate limit conn-limit SNMP traps |
|
|
Upgrade failure on FMC on GCP 000_start/112_CF_check.sh |
|
|
ASAv on Hyper-v encountering boot loop issues when running netvsc driver |
|
|
Detection engine Folder is huge in size for FTD backups |
|
|
ASA traceback and reload due to memory corruption in IPsec SA pointers |
|
|
GeoDB content is not restored when restoring a backup to a freshly deployed FMC |
|
|
High network latency observed on ASAv |
|
|
Unable to upload VPN client profile package under Objects > Object Management > VPN > Secure client File to FMC while logged in via External User. |
|
|
WPK node rebooted with lina core while trying to form cluster in snp_nat_allocate_port |
|
|
Device goes into bootloop due to missing librte_mbuf.so.22 and librte_ring.so.22 |
|
|
Enhance UI error messages to inform users that deployment is not allowed due to version mismatch. |
|
|
Add validation on FMC UI to prevent admin to configure more than allowed IKE policies |
|
|
FTD not fetching CRL through the SSE connector |
|
|
ASA/FTD traceback and reload in Lina |
|
|
Few Chassis devices are not visible to assign the policies |
|
|
FP2110 Critical fault alerts for remote users |
|
|
Deployment failure due to unrecognized command "vpn-simultaneous-logins none" |
|
|
ASA/FTD Traceback and reload in L2 table creation failure |
|
|
FTD silently drops out of order packets |
|
|
removing all usages of a DHCP IPv6 pool object from FTD interface config does not delete the object from FTD |
|
|
ASA may traceback during manual failover |
|
|
FPR 3110 MI (shared subinterface) - Traffic outage when disabling multicast routing on one FW instance |
|
|
Multiple issues with either Interface not coming up or CRC errors with 25/50G LR SFP |
|
|
FTD , dcosAG continuously crashing |
|
|
Portmanager generating a silent link down event for a port-channel without a corresponding portmanager log entry. |
|
|
Warning about the usage of failsafe-exit |
Open Issues
Open issues in Version 10.1.0
This table lists the open issues in this specific software release.
Table last updated: 2026-09-21
|
ID |
Headline |
|---|---|
| CSCww07550 |
9.24.10/SecGW TCP 450B Unstable - intermittent cluster-bad-ifc-goid-in-trailer |
|
Secure Firewall 200 upgrade fails with sqlite errors |
|
|
After redistribution, moved nat-t ipsec vpn sessions fail to offload inbound traffic (processed as non-offloaded) |
Open issues in Version 10.0.0
This table lists the open issues in this specific software release.
Table last updated: 2026-09-18
|
ID |
Headline |
|---|---|
|
1240/1250 VPN IKEv2 TCP 450B w/ AVC degraded ~4-5% |
|
|
10.0 vs 7.7: UDP Throughput 512B with Elephant Flow 22% lower on 1010 |
|
|
FTD Performance down -8% on 1200 (Snort side) and 1010/ISA3k |
|
|
Move SQLite databases under /var/sf/sqlite folder to the high endurance partition of FTDs |
|
|
SSP UZTNA Throughput Degradation |
|
|
FMC UI not accessible for few min due to MySQLUtil [ERROR] UpdateTable: MySQL error 2002 |
|
|
Secure Firewall 200 not available after backup/restore when using an access control rule with URL categories |
|
|
Policy not marked out of date after a vdb upgrade as part of FMC upgrade |
|
|
FTD upgrade state stuck "in progress" until shown as failed task, even though upgrade verified to be successful |
|
|
FDM RA VPN SAML Authentication Failed When SP Base-URL Is Using HTTPS With Default Port 443 |
|
|
Splunk profiles with FTD data interface option do not emit events over data interface |
|
|
Hardware errors during boot-up sequence on the Secure Firewall 6100 |
Compatibility
Before you upgrade or reimage, make sure the target version is compatible with your deployment. If you cannot upgrade or reimage due to incompatibility, contact your Cisco representative or partner for refresh information.
For compatibility information, see:
Upgrade and downgrade
Choosing your upgrade target
Go directly to the latest release possible to minimize upgrade and other impact. This is because features, enhancements, and critical fixes can skip "future" releases that are ahead by version, but not by release date. For example, if you are up-to-date within major Version A, upgrading to dot-zero Version B can deprecate features and fixes.
If you cannot go to the latest release, at least make sure your current version was released on a date before your target version. In the following table, confirm your current version is listed next to your target version. If it is not, choose a later target.
|
Target version |
Current version: confirm yours is listed. |
|||||
|---|---|---|---|---|---|---|
|
from 7.3 |
from 7.4 |
from 7.6 |
from 7.7 |
from 10.0 |
||
|
to 10.1.0 |
2026-09-21 |
7.3.0–7.3.1 |
7.4.0–7.4.8 |
7.6.0–7.6.6 |
7.7.0–7.7.13 |
10.0.0–10.0.2 |
|
to 10.0.2 |
2026-09-15 |
7.3.0–7.3.1 |
7.4.0–7.4.8 |
7.6.0–7.6.6 |
7.7.0–7.7.13 |
10.0.0–10.0.1 |
|
to 10.0.0 |
2025-12-03 |
7.3.0–7.3.1 |
7.4.0–7.4.3 |
7.6.0–7.6.3 |
7.7.0–7.7.11 |
— |
Upgrading a patched deployment
Critical fixes in patches/vulnerability (fourth-digit) releases can also skip future releases. If you depend on these critical fixes, verify that your target version contains them. For a full list of release dates, see Cisco Secure Firewall Device Manager New Features by Release.
Supported upgrades and downgrades
This section summarizes upgrade and downgrade capability. For help with:
-
Choosing an upgrade target, see Choosing your upgrade target.
-
Upgrade and downgrade procedures, including general guidelines, best practices, and troubleshooting, see the upgrade guide for the version you are currently running: https://www.cisco.com/go/ftd-upgrade.
-
Any upgrade or downgrade issues for this specific release, see Open issues in Version 10.0.0 and Known issues with upgrade.
Supported upgrades
This table shows the supported direct upgrades for Firewall Threat Defense software.
Note |
Patches can change the fourth digit only. You cannot upgrade directly to a patch from a previous major or maintenance release. |
|
Current version |
Target software version |
|||||||
|---|---|---|---|---|---|---|---|---|
|
to 10.x |
7.7 |
7.6 |
7.4 |
7.3 |
7.2 |
7.1 |
7.0 |
|
|
from 10.x |
YES |
— |
— |
— |
— |
— |
— |
— |
|
from 7.7 |
YES |
YES |
— |
— |
— |
— |
— |
— |
|
from 7.6 |
YES |
YES |
YES |
— |
— |
— |
— |
— |
|
from 7.4 |
YES |
YES |
YES |
YES |
— |
— |
— |
— |
|
from 7.3 |
YES |
YES |
YES |
YES |
YES |
— |
— |
— |
|
from 7.2 |
— |
YES |
YES |
YES |
YES |
YES |
— |
— |
|
from 7.1 |
— |
— |
YES |
YES |
YES |
YES |
YES |
— |
|
from 7.0 |
— |
— |
— |
YES |
YES |
YES |
YES |
YES |
|
from 6.4 |
— |
— |
— |
— |
— |
— |
— |
YES |
Supported FXOS versions for Firepower 4100/9300 upgrades
For the Firepower 4100/9300, this table lists companion FXOS versions. If a chassis upgrade is required, Firewall Threat Defense upgrade is blocked. In most cases we recommend the latest build in each version; for minimum builds see the Cisco Secure Firewall Threat Defense Compatibility Guide.
|
Target Firewall Threat Defense version |
Minimum FXOS version |
|---|---|
|
10.x |
2.18.0 |
|
7.7 |
2.17.0 |
|
7.6 |
2.16.0 |
|
7.4.1–7.4.x |
2.14.1 |
|
7.4.0 |
— |
|
7.3 |
2.13.0 |
|
7.2 |
2.12.0 |
|
7.1 |
2.11.1 |
|
7.0 |
2.10.1 |
|
6.7 |
2.9.1 |
|
6.6 |
2.8.1 |
|
6.4 |
2.6.1 |
Supported downgrades
If an upgrade succeeds but the system does not function to your expectations, you may be able to return to a previous version. For general information, particularly on common scenarios where returning to a previous version is not supported or recommended, see the upgrade guide: https://cisco.com/go/ftd-upgrade.
Known issues with upgrade
This section lists upgrade limitations and feature impact for this release. For general guidelines and best practices, see the Secure Firewall Threat Defense upgrade guides for Firewall Device Manager.
Known issues with upgrade
This table lists upgrade limitations for this release.
|
Current version |
Issue |
Details |
||
|---|---|---|---|---|
|
7.7 and earlier |
Revert prohibited: Firewall Threat Defense Virtual Version 10+ to Version 7.7 and earlier. |
Security enhancements to the startup framework (bootloader firmware) mean that you cannot revert Firewall Threat Defense Virtual upgrades from Version 10+ to Version 7.7 and earlier. After upgrade, we also recommend you migrate configurations to freshly deployed Version 10+ instances and decommission the old ones. |
||
|
7.6.1 and earlier |
Some destinations might be unreachable after upgrade for devices with a large number of routes. |
Version 7.6.2 limits the ASP routing table to 1,000,000 routes. Version 7.6.4 increases the limit to 2,000,000 routes. After upgrading, routes above the applicable limit might not be installed, and traffic to those destinations might be dropped. Before upgrading, review the device’s route count. Use route summarization or route filtering to reduce the number of routes and keep the total below 1,000,000 when upgrading to Version 7.6.2–7.6.3, or below 2,000,000 when upgrading to Version 7.6.4–Version 10.0.x. Refer to: CSCwo44267.
|
||
|
7.4.x and earlier |
Do not upgrade the Firepower 1010 if a subinterface uses VLAN 1 |
For models with built-in switches, you cannot create a subinterface using VLAN 1. VLAN 1 is reserved for the logical VLAN interface for switch ports. If you upgrade the Firepower 1010 to Version 7.6+ later, and you have assigned VLAN 1 to a subinterface, you must first change the VLAN ID for your subinterface to a new VLAN. After upgrading, if present, VLAN 1 will be removed from the subinterface. |
Features with upgrade impact
A feature has upgrade impact if upgrading and deploying can cause the system to process traffic or otherwise act differently without any other action on your part. This is especially common with new threat detection and application identification capabilities. A feature can also have upgrade impact if upgrading requires that you take action before or after upgrade to avoid an undesirable outcome; for example, if you must change a configuration.In the following table, check all releases between your current and target version.
Note |
Minimize upgrade and other impact by going directly to the latest maintenance release in your chosen version. See Choosing your upgrade target. |
|
Target version |
Features |
|---|---|
| 10.0.0+ |
|
|
|
|
|
|
Feedback