Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
Cisco patches CVE-2026-20349, a high-severity unauthenticated DoS in ASA and FTD VPN services now added to CISA's KEV.
CVE-2026-20349 affects the Remote Access SSL VPN service in Cisco Secure Firewall ASA and FTD software, where specially crafted unauthenticated HTTP requests can cause appliances to reload, creating a denial of service. Cisco confirmed active exploitation observed in August 2026 and released hot fixes for ASA versions 9.16 through 9.24 and FTD versions 7.0 through 10.0. The flaw was added to CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of August 14, 2026 for US civilian federal agencies. No workarounds or indicators of compromise are available.
- Affects IKEv2 Remote Access VPN, SSL VPN and ZTNA features when SSL listen sockets are active
- Unauthenticated crafted HTTP requests cause unexpected appliance reloads and DoS
- Hot fixes cover ASA 9.16-9.24 and FTD 7.0-10.0; no workarounds available
- KEV remediation deadline for US civilian federal agencies is August 14, 2026
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20349 | Unauthenticated Remote DoS in Cisco ASA/FTD SSL VPN Service CVE-2026-20349 is a vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software, caused by insufficient error checking when processing HTTP requests. An unauthenticated, remote attacker can trigger it by sending a crafted HTTP request to the SSL VPN service on an affected device. A successful exploit causes the device to reload unexpectedly, resulting in a denial-of-service condition; no credentials or user interaction are required, and confidentiality and integrity are not affected. Any organization running ASA or FTD software with the Remote Access SSL VPN service enabled is affected, especially devices whose VPN interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-11 and is reported as exploited in the wild, though no public proof-of-concept is known. Do: Upgrade ASA and FTD devices to the fixed releases listed in the Cisco PSIRT advisory for CVE-2026-20349. Until patching is complete, verify whether the Remote Access SSL VPN service is enabled and internet-exposed, restrict access to trusted sources where possible, and check logs for unexpected device reloads. Federal agencies must apply mitigations per CISA BOD 26-04 timelines. | 8.6 | 2% | KEV |
| masson the order of 100,000s of internet-exposed ASA/FTD devices (only those with the Remote Access SSL VPN service enabled) |
Full article285 words · extracted from helpnetsecurity.com · click to collapse
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed.
The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by August 14, 2026.
Details about the attacks are currently under wraps. Cisco only shared that its Product Security Incident Response Team (PSIRT) became aware of active exploitation of this vulnerability in August 2026.
About CVE-2026-20349
CVE-2026-20349 affects the Remote Access SSL VPN service for:
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Secure Firewall Threat Defense (FTD) Software
Affected features are IKEv2 Remote Access VPN (with client services), SSL VPN, and Zero Trust Network Access (ZTNA). An appliance is vulnerable to attack if it runs an affected software version and if one of these features is enabled (i.e., the SSL listen sockets are active).
CVE-2026-20349 can be triggered by attackers via a specially crafted HTTP request to the vulnerable service. The request could cause the security appliances to reload unexpectedly, resulting in a denial of service condition.
An attacker can exploit this vulnerability without needing to authenticate or trick a user into any action.
To address the issue, Cisco has issued hot fixes covering ASA software versions 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, and FTD software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. There are no available workarounds, and no specific indicators of compromise.
According to the security advisory, the vulnerability was found by Cisco during internal security testing, but also reported by security researcher Valerio Brussani.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/13/cve-2026-20349-cisco-firewalls-dos/