CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

August 12, 2026

Cisco has disclosed that a high-severity vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software is being actively exploited in the wild. Tracked as CVE-2026-20349 with a CVSS score of 8.6, the flaw stems from insufficient error checking when processing HTTP requests, allowing an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition by sending a crafted HTTP request to the Remote Access SSL VPN service.

Successful exploitation causes the affected device to reload, disrupting network security operations. The vulnerability impacts devices running vulnerable versions of ASA or FTD with specific configurations, including IKEv2 Remote Access VPN, WebVPN, or Zero Trust Network Access enabled. Cisco has released software updates for all affected versions, but there are no workarounds. The issue was discovered during internal security testing and also reported by Valerio Brussani.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20349 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch agencies to apply fixes by August 14, 2026. While details of the attacks remain undisclosed, organizations using affected Cisco products are urged to patch immediately to mitigate risk.

CVEs: CVE-2026-20349

Companies: Cisco, CISA

Products: Cisco Secure Firewall ASA Software, Cisco Secure Firewall Threat Defense (FTD) Software