Known Vulnerabilities for Web Security Appliance by Cisco

Listed below are 10 of the newest known vulnerabilities associated with "Web Security Appliance" by "Cisco".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

More device details and information can be found at device.report here: Cisco Web Security Appliance

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-20106 json A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Securi... Not Provided 2026-03-04 2026-03-11
CVE-2026-20105 json A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwar... Not Provided 2026-03-04 2026-03-04
CVE-2026-20103 json A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwar... Not Provided 2026-03-04 2026-03-04
CVE-2026-20049 json A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffi... Not Provided 2026-03-04 2026-03-04
CVE-2026-20039 json A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Fi... Not Provided 2026-03-04 2026-03-05
CVE-2026-20021 json A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Fir... Not Provided 2026-03-04 2026-03-04
CVE-2026-20009 json A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall... Not Provided 2026-03-04 2026-03-05
CVE-2026-20008 json A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) So... Not Provided 2026-03-04 2026-03-05
CVE-2026-3470 json A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data cor... Not Provided 2026-03-31 2026-03-31
CVE-2026-3469 json A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, al... Not Provided 2026-03-31 2026-03-31

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationCiscoWeb Security Appliancewsa10.5.0-fcs-000
ApplicationCiscoWeb Security Appliance9.5_base
ApplicationCiscoWeb Security Appliance9.5.0-444
ApplicationCiscoWeb Security Appliance9.5.0-235
ApplicationCiscoWeb Security Appliance9.1_base
ApplicationCiscoWeb Security Appliance9.1.2-039
ApplicationCiscoWeb Security Appliance9.1.2-022
ApplicationCiscoWeb Security Appliance9.1.1-074
ApplicationCiscoWeb Security Appliance9.1.0-000
ApplicationCiscoWeb Security Appliance9.0_base
ApplicationCiscoWeb Security Appliance9.0.1-162
ApplicationCiscoWeb Security Appliance9.0.0-193
Operating
System
CiscoWeb Security Appliance9.0.0-193
ApplicationCiscoWeb Security Appliance8.8.0-000
ApplicationCiscoWeb Security Appliance8.5_base
ApplicationCiscoWeb Security Appliance8.5.3-055
ApplicationCiscoWeb Security Appliance8.5.2-027
Operating
System
CiscoWeb Security Appliance8.5.0-497
ApplicationCiscoWeb Security Appliance8.5.0-000
ApplicationCiscoWeb Security Appliance8.0.7
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report