VMTech
Discuss a project

Cisco ASA and FTD flaw under active exploitation can cause remote DoS

Cisco ASA and FTD flaw under active exploitation can cause remote DoS

Cisco has warned that attackers are actively exploiting CVE-2026-20349, a high-severity vulnerability in Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. The flaw carries a CVSS score of 8.6 and can allow an unauthenticated remote attacker to cause an affected device to reload, producing a denial-of-service condition.

The issue is present in vulnerable ASA and FTD installations with one or more affected remote-access configurations. Cisco said exploitation requires a crafted HTTP request sent to the Remote Access SSL VPN service on an affected device.

HTTP processing error can reload affected devices

Cisco attributes CVE-2026-20349 to insufficient error checking while processing HTTP requests. A successful attempt can reload the firewall rather than grant the attacker access or execution. Even so, a forced reload can interrupt remote connectivity and security services provided by the appliance.

The vendor said it became aware of active exploitation earlier in August. It found the issue during internal security testing and also credited Valerio Brussani with independently discovering and reporting the vulnerability. Cisco has not disclosed details about the attacks, their operators or origins, targeted organisations, or whether exploitation attempts were successful.

VPN and ZTNA configurations are in scope

Affected configurations include IKEv2 Remote Access VPN with client services, enabled through the crypto ikev2 enable <interface_name> client-services port <port_numbers> setting. SSL-VPN deployments using webvpn enable <interface_name> and Zero Trust Network Access2 deployments using zero-trust enable are also listed by Cisco.

The affected ASA release lines are 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24. Cisco lists fixed releases 9.16.4.50, 9.18.4.50, 9.20.4.235, 9.22.3.191, 9.23.1.211 and 9.24.1.221 respectively. For FTD, the company has issued platform-specific hotfix packages for release trains 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0.

The incident joins the Cisco-related security activity examined in Cisco vulnerabilities and active attack chains, where active vulnerabilities and attack chains underscored the operational consequences of exposed infrastructure. In this case, Cisco says no workaround addresses the defect, making its listed fixed releases and hotfixes the available remediation path.

CISA adds the flaw to its exploited-vulnerability list

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch agencies are required to apply the fixes by August 14, 2026.

Businesses using ASA or FTD should inventory versions and enabled remote-access services, establish whether the listed configurations are present, and apply Cisco’s appropriate fixed release or FTD hotfix. Because exploitation is already known and no workaround is available, patch prioritisation should account for the availability risk to VPN and ZTNA access.

#cisco#firewallsecurity#vulnerability#patchmanagement
Open analytics
On the site 1 views
min read 3 12.08.2026
Instagram

Cisco ASA and FTD flaw under active exploitation can cause remote DoS

Open the post on Instagram ↗