Cisco ASA / Firepower
Cisco · current 9.24
The current version of Cisco ASA / Firepower is 9.24 (as of 26/07/2026). patchletter checks the official source daily and emails you every new release.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
- CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access VulnerabilityRansomware
9.1 critical · over the network, without login · CISA deadline was 4 Oct 23
7.5 high · over the network, without login · CISA deadline was 7 Mar 24
6.1 medium · over the network, without login, needs user action · CISA deadline was 3 May 22
- CVE-2025-20333Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
9.9 critical · over the network, with a basic account · CISA deadline was 26 Sept 25
- CVE-2016-6366Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 14 Jun 22
- CVE-2024-20353Cisco ASA and FTD Denial of Service Vulnerability
8.6 high · over the network, without login · CISA deadline was 1 May 24
- CVE-2025-20362Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
8.6 high · over the network, without login · CISA deadline was 26 Sept 25
- CVE-2026-20349Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
8.6 high · over the network, without login · CISA deadline was 14 Aug
- CVE-2016-6367Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability
7.8 high · locally only, with a basic account · CISA deadline was 14 Jun 22
- CVE-2018-0296Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
7.5 high · over the network, without login · CISA deadline was 3 May 22
- CVE-2020-3452Cisco ASA and FTD Read-Only Path Traversal Vulnerability
7.5 high · over the network, without login · CISA deadline was 3 May 22
- CVE-2014-2120Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
6.1 medium · over the network, without login, needs user action · CISA deadline was 3 Dec 24
- CVE-2024-20359Cisco ASA and FTD Privilege Escalation Vulnerability
6.0 medium · locally only, with admin rights only · CISA deadline was 1 May 24
- CVE-2024-20481Cisco ASA and FTD Denial-of-Service Vulnerability
5.8 medium · over the network, without login · CISA deadline was 14 Nov 24
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
Cisco ASA / Firepower at a glance
Cisco ASA is a long-established firewall and VPN platform (and its FTD successor line) common in enterprises. Cisco ships ASA software releases plus security advisories; as a perimeter and VPN device that has seen actively exploited flaws, prompt patching is essential.
For admins never expose the management interface to untrusted networks, prioritize VPN-related advisories, and pick the right ASA release per platform. Take a config backup before upgrading, mind the order on failover pairs, and verify VPN tunnels and policies afterwards. Track the software version and its support lifecycle per appliance — hardware past support receives no fixes and should be in the replacement plan. Subscribe to Cisco's security advisories; patchletter flags new ASA releases.
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 9.24 | STABLE | 26/07/2026 | Release notes → |
Frequently asked questions
- What is the latest version of Cisco ASA / Firepower?
- Cisco ASA / Firepower 9.24, released 26/07/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Cisco ASA / Firepower release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Cisco ASA / Firepower updates?
- Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.
Never miss a Cisco ASA / Firepower update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch Cisco ASA / FirepowerEmbed this badge
Shows the current Cisco ASA / Firepower version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/cisco-asa)https://patchletter.com/badge/cisco-asa.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).