Cisco Secure Firewall ASA & FTD — CVE-2026-20349
Actively exploited zero-day lets an unauthenticated attacker crash Cisco ASA and FTD firewalls with a crafted request to the Remote Access SSL VPN service.
- Target
- Cisco Secure Firewall ASA & FTD — CVE-2026-20349
- Date public
- 11 August 2026
- Sector
- Technology
- Attack type
- Vulnerability Exploit
- Threat actor
- Unattributed
- Severity
- High
- Region
- Global
Cisco disclosed CVE-2026-20349 in August 2026, a vulnerability in the Remote Access SSL VPN component of Cisco Secure Firewall ASA and Secure Firewall Threat Defence (FTD). The flaw carries a CVSS base score of 8.6 and stems from improper handling of HTTP requests to the Remote Access SSL VPN service. A remote, unauthenticated attacker can send a specially crafted HTTP request to a vulnerable appliance and force it to reload, dropping the device into a denial-of-service condition. Repeated requests keep it there. Cisco has said it became aware of active exploitation attempts before the fix was public, which places this in the zero-day category rather than the routine patch cycle.
This is an availability attack, not a data-theft one, and the distinction matters for how defenders should read it. There is no cookie forgery, no unauthenticated VPN session, no path to code execution described in the advisory. What an attacker gets is the ability to knock an internet-facing firewall offline at will from anywhere on the internet, with no credentials. For an organisation that terminates its remote-access VPN on the affected appliance, a sustained exploit does not just crash a box; it removes the front door the workforce uses to reach internal systems. The affected configurations are the common ones: devices running IKEv2 Remote Access VPN with client services, SSL VPN, or Zero Trust Network Access. Cisco issued hot fixes spanning ASA 9.16 through 9.24 and FTD 7.0 through 10.0, and has stated there is no workaround for organisations that cannot patch.
CISA added CVE-2026-20349 to the Known Exploited Vulnerabilities catalogue on 11 August 2026 and set a federal civilian agency remediation deadline of 14 August 2026, a three-day window that signals how seriously the agency is treating in-the-wild use. Cisco has not published details of the observed attacks or attributed them to a named actor.
The editorial significance sits, as it usually does with perimeter appliances, one layer below the CVE. ASA and FTD are among the most widely deployed remote-access VPN platforms across the UK financial-services estate, and a flaw that takes the appliance down is a business-continuity event as much as a security one. It belongs to the same recurring pattern the catalogue tracks in the PAN-OS GlobalProtect stub (pan-os-globalprotect-cve-2026-0257): the internet-facing box that concentrates remote access becomes the single point whose failure, whether by data bypass or by forced reload, has an outsized blast radius. The defender question here is less about patch timing alone and more about whether remote access has a resilient fallback when the primary appliance is deliberately crashed, and whether the VPN tier is segmented from the systems it fronts.
This is the catalogue’s reference stub for the CVE. A deep-dive will follow if a named victim outage is publicly attributed to a CVE-2026-20349 chain, or if Cisco publishes a fuller account of the exploitation activity.
Sources
- CISA — Adds Three Known Exploited Vulnerabilities to Catalog (11 August 2026) // primary
- CISA — Known Exploited Vulnerabilities Catalog // primary
- BleepingComputer — Cisco warns of ASA and FTD VPN flaw exploited to crash devices // reporting
- The Hacker News — Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS // reporting
- SecurityWeek — Cisco Patches Firewall Zero-Day Exploited for DoS Attacks // reporting