ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

highExploit / PoC exploited in the wildimportance 72CVE-2026-20349
AI summary · glm-5.3-flash

Cisco warns actively exploited flaw CVE-2026-20349 lets unauthenticated attackers crash ASA and FTD firewalls via SSL VPN; CISA added it to KEV.

Cisco fixed CVE-2026-20349 (CVSS 8.6) in Secure Firewall ASA and FTD software, insufficient error checking in HTTP request processing that lets unauthenticated remote attackers force device reloads via crafted requests to the Remote Access SSL VPN service. Hotfixes cover ASA 9.16 through 9.24 and FTD 7.0 through 10.0, and there are no workarounds; Cisco confirmed active exploitation earlier in August but did not name the actor or targets. The flaw was found during internal security testing. CISA added it to the KEV catalog, requiring federal civilian agencies to patch by August 14, 2026.

  • CVE-2026-20349 (CVSS 8.6) causes device reloads via crafted HTTP requests to SSL VPN
  • Affects ASA 9.16-9.24 and FTD 7.0-10.0; hotfixes available, no workarounds
  • CISA added the flaw to KEV; federal agencies must patch by August 14, 2026
  • Found during Cisco internal testing; no actor or target details disclosed

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20349
Unauthenticated Remote DoS in Cisco ASA/FTD SSL VPN Service

CVE-2026-20349 is a vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software, caused by insufficient error checking when processing HTTP requests. An unauthenticated, remote attacker can trigger it by sending a crafted HTTP request to the SSL VPN service on an affected device. A successful exploit causes the device to reload unexpectedly, resulting in a denial-of-service condition; no credentials or user interaction are required, and confidentiality and integrity are not affected. Any organization running ASA or FTD software with the Remote Access SSL VPN service enabled is affected, especially devices whose VPN interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-11 and is reported as exploited in the wild, though no public proof-of-concept is known.

Do: Upgrade ASA and FTD devices to the fixed releases listed in the Cisco PSIRT advisory for CVE-2026-20349. Until patching is complete, verify whether the Remote Access SSL VPN service is enabled and internet-exposed, restrict access to trusted sources where possible, and check logs for unexpected device reloads. Federal agencies must apply mitigations per CISA BOD 26-04 timelines.

8.62% KEV
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
masson the order of 100,000s of internet-exposed ASA/FTD devices (only those with the Remote Access SSL VPN service enabled)
Full article427 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 12, 2026Network Security / Vulnerability

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild.

The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger a denial-of-service (DoS) condition.

"An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device," Cisco said in a Tuesday advisory. "A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition."

The security defects impact devices running a vulnerable version of Secure Firewall ASA Software or Cisco Secure FTD Software and have one or more of the vulnerable configurations listed below -

  • IKEv2 Remote Access VPN (with client services) - crypto ikev2 enable <interface_name> client-services port <port_numbers>
  • SSL-VPN - webvpn enable <interface_name>
  • Zero Trust Network Access2 - zero-trust enable

The following versions of ASA and FTD are affected -

  • ASA 9.161 - Fixed in 89.16.4.50)
  • ASA 9.181 - Fixed in 89.18.4.50)
  • ASA 9.20 - Fixed in 9.20.4.235)
  • ASA 9.22 - Fixed in 9.22.3.191)
  • ASA 9.23 - Fixed in 9.23.1.211)
  • ASA 9.24 - Fixed in 9.24.1.221)
  • FTD 7.0 - Fixed in
    • Cisco_FTD_Hotfix_GC-7.0.9.1-1.sh.REL.tar
    • Cisco_FTD_SSP_FP1K_Hotfix_GC-7.0.9.1-1.sh.REL.tar
    • Cisco_FTD_SSP_FP2K_Hotfix_GC-7.0.9.1-1.sh.REL.tar
    • Cisco_FTD_SSP_Hotfix_GC-7.0.9.1-1.sh.REL.tar
  • FTD 7.2 - Fixed in
    • Cisco_FTD_Hotfix_HM-7.2.11.1-2.sh.REL.tar
    • Cisco_FTD_SSP_FP1K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
    • Cisco_FTD_SSP_FP2K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
    • Cisco_FTD_SSP_FP3K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
    • Cisco_FTD_SSP_Hotfix_HM-7.2.11.1-2.sh.REL.tar
  • FTD 7.4 - Fixed in
    • Cisco_FTD_Hotfix_HK-7.4.7.1-1.sh.REL.tar
    • Cisco_FTD_SSP_FP1K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
    • Cisco_FTD_SSP_FP2K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
    • Cisco_FTD_SSP_FP3K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
    • Cisco_FTD_SSP_Hotfix_HK-7.4.7.1-1.sh.REL.tar
    • Cisco_Secure_FW_TD_4200_Hotfix_HK-7.4.7.1-1.sh.REL.tar
  • FTD 7.6 (Fixed in
    • Cisco_FTD_Hotfix_DD-7.6.4.1-2.sh.REL.tar
    • Cisco_FTD_SSP_FP1K_Hotfix_DD-7.6.4.1-2.sh.REL.tar
    • Cisco_FTD_SSP_FP3K_Hotfix_DD-7.6.4.1-2.sh.REL.tar
    • Cisco_FTD_SSP_Hotfix_DD-7.6.4.1-2.sh.REL.tar
    • Cisco_Secure_FW_TD_4200_Hotfix_DD-7.6.4.1-2.sh.REL.tar
  • FTD 7.7 - Fixed in
    • Cisco_FTD_Hotfix_AN-7.7.11.1-2.sh.REL.tar
    • Cisco_FTD_SSP_FP1K_Hotfix_AN-7.7.11.1-2.sh.REL.tar
    • Cisco_FTD_SSP_FP3K_Hotfix_AN-7.7.11.1-2.sh.REL.tar
    • Cisco_FTD_SSP_Hotfix_AN-7.7.11.1-2.sh.REL.tar
    • Cisco_Secure_FW_TD_1200_Hotfix_AN-7.7.11.1-2.sh.REL.tar
    • Cisco_Secure_FW_TD_4200_Hotfix_AN-7.7.11.1-2.sh.REL.tar
  • FTD 10.0 - Fixed in
    • Cisco_FTD_Hotfix_S-10.0.0.1-2.sh.REL.tar
    • Cisco_FTD_SSP_FP1K_Hotfix_S-10.0.0.1-2.sh.REL.tar
    • Cisco_FTD_SSP_FP3K_Hotfix_S-10.0.0.1-2.sh.REL.tar
    • Cisco_FTD_SSP_Hotfix_S-10.0.0.1-2.sh.REL.tar
    • Cisco_Secure_FW_TD_200_Hotfix_R-10.0.0.1-2.sh.REL.tar
    • Cisco_Secure_FW_TD_1200_Hotfix_S-10.0.0.1-2.sh.REL.tar
    • Cisco_Secure_FW_TD_4200_Hotfix_S-10.0.0.1-2.sh.REL.tar
    • Cisco_Secure_FW_TD_6100_Hotfix_S-10.0.0.1-2.sh.REL.tar

Cisco said there are no workarounds that address the flaw, adding it became aware of active exploitation earlier this month. The network equipment maker said the issue was found during internal security testing. It also credited Valerio Brussani for separately discovering and reporting the vulnerability.

There are currently no details about the nature of the attacks, the identity and origins of the threat actor exploiting the vulnerability, what organizations have been targeted, and if any of those efforts were successful.

The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by August 14, 2026.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html