<- ALL CYBER NEWS

High

Cisco, ASA, FTD, Firewall, CVE-2026-20349, DoS, SSL VPN, Exploited

Cisco ASA/FTD CVE-2026-20349 Exploited: Remote DoS

Cisco ASA/FTD CVE-2026-20349 (CVSS 8.6) is exploited in the wild for unauthenticated remote DoS via the SSL VPN. Affected versions and fixes.

Cisco ASA/FTD CVE-2026-20349 Exploited in the Wild for Remote DoS

Cisco has confirmed that CVE-2026-20349, a CVSS 8.6 flaw in Secure Firewall ASA and FTD software, is being exploited in the wild. A single crafted HTTP request to the Remote Access SSL VPN service can make an affected firewall reload, giving an unauthenticated remote attacker a denial-of-service condition with no credentials required. Devices with SSL-VPN, IKEv2 Remote Access VPN, or Zero Trust Network Access configurations are affected, and Cisco has shipped fixed releases across the 9.16 through 9.24 trains. The advisory landed on August 12, 2026, alongside confirmation of active exploitation.

The flaw is an insufficient-error-checking issue (CWE-244) in how the VPN service processes HTTP requests. Because the vulnerable listener parses the incoming request before any authentication happens, an attacker only has to send one malformed request to the SSL VPN interface to crash the device. That is the uncomfortable shape of this bug: it is "only" a denial of service, but on a firewall that terminates remote-access VPN, a reload is an outage of the exact control that remote workers and site-to-site tunnels depend on. EPSS sits around the 56th percentile, which understates a flaw Cisco already says is being used.

There is no clever partial mitigation here, and admins have been learning that the hard way. Disabling the clientless WebVPN portal does not help, because the listener still parses the HTTP handshake. Control-plane rate limiting does not help either, because a single request is enough to trigger the crash, so throttling only slows the scanning, not the outage. The only real controls are the patch and, as a stopgap, restricting who can even reach the SSL VPN port.

How do I know if my Cisco firewall is affected?

Check both configuration and version. The device is exposed if it runs a vulnerable ASA or FTD release and has one or more of the reachable VPN configurations enabled: webvpn enable (SSL-VPN), IKEv2 Remote Access VPN with client services, or zero-trust enable (ZTNA). Affected trains span ASA 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, each with a corresponding fixed build. If you terminate remote-access VPN on ASA or FTD, assume you are in scope until you have matched your version to a fixed release.

What can defenders do besides patch?

Patch to the fixed train for your branch as the primary fix, since Cisco offers no reliable configuration workaround. Until then, restrict inbound access to the SSL VPN service to known client IP ranges or trusted geographies upstream, which shrinks who can send the trigger. For detection, watch for unexpectedly short uptime and repeated reloads across an active/standby pair, and inspect show crashinfo for traces in the WebVPN or HTTP processing threads right before a watchdog or segmentation failure.

Detail

Value

CVE

CVE-2026-20349

Severity

CVSS 8.6 (CWE-244, insufficient error checking)

Impact

Unauthenticated remote DoS (device reload)

Status

Exploited in the wild (Cisco advisory, Aug 12, 2026)

Trigger

Crafted HTTP request to Remote Access SSL VPN

Affected configs

SSL-VPN, IKEv2 RA VPN, ZTNA

Fixed

ASA/FTD 9.16 through 9.24 fixed trains

Our read

Continuous verification is the whole point of an edge device like this. A firewall is a control you place in the traffic path to enforce policy, and a pre-authentication crash bug turns that control into a single point of outage an anonymous attacker can flip at will. Our analysis of CISA's 2025 KEV data found that 67% of the year's actively exploited vulnerabilities would have been missed by an annual pentest, and an internet-facing VPN concentrator being crashed on demand is exactly the exposure a once-a-year review overlooks. Patch the affected train, lock the SSL VPN port to trusted sources, and verify that exposure continuously rather than assuming an appliance labeled "security" is secure.

Reporting by The Hacker News; severity, affected versions, and exploitation status per Cisco's security advisory and NVD. Sources linked above.

Related: Progress Kemp LoadMaster CVE-2026-8037 in CISA KEV · Arista VeloCloud CVE-2026-16812 exploited zero-day

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.