Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NSummary
CVE-2026-20070 is a medium-severity Basic XSS (CWE-80) vulnerability in Cisco Adaptive Security Appliance Software. Its CVSS base score is 6.1 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 18th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and SC-7 (Boundary Protection) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-9469
Vulnerability Data
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a…
more
browser that is accessing an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by persuading a user to follow a link to a malicious website that is designed to submit malicious input to the affected application. A successful exploit could allow the attacker to execute arbitrary HTML or script code in the browser in the context of the VPN web server.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
XSS in public-facing VPN web services directly enables exploitation of the application via malicious input delivery (T1190).
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly requires validation of user-supplied HTTP input to the VPN web services, blocking the unsanitized data that enables the CWE-80 XSS flaw.
Boundary-protection mechanisms (e.g., WAF rules or HTTP filtering at the firewall perimeter) can inspect and drop malicious script payloads targeting the ASA/FTD VPN portal.
Malicious-code protections on the device or client browser can detect and neutralize injected scripts delivered via the crafted link described in the CVE.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require output encoding and input validation that prevent basic XSS.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development catches unneutralized script tags before release.
Secure SDLC mandates input validation and output encoding that directly prevent basic XSS.
Application security requirements explicitly call for neutralization of script-related HTML tags.
Secure coding standards require proper escaping of <, >, & to block XSS.
Web filtering can block some reflected XSS payloads at the network edge.