ZeroHour

Search: “ftd”

107 items

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco warns actively exploited flaw CVE-2026-20349 lets unauthenticated attackers crash ASA and FTD firewalls via SSL VPN; CISA added it to KEV.

Cisco fixed CVE-2026-20349 (CVSS 8.6) in Secure Firewall ASA and FTD software, insufficient error checking in HTTP request processing that lets unauthenticated remote attackers force device reloads via crafted requests to the Remote Access SSL VPN service. Hotfixes cover ASA 9.16 through 9.24 and FTD 7.0 through 10.0, and there are no workarounds; Cisco confirmed active exploitation earlier in August but did not name the actor or targets. The flaw was found during internal security testing. CISA added it to the KEV catalog, requiring federal civilian agencies to patch by August 14, 2026.

The Hacker News · Aug 12, 2026Exploit / PoC in the wildCVE-2026-20349

Cisco ASA and FTD DoS Vulnerability Exploited in the Wild (CVE-2026-20349)

Cisco patched actively exploited high-severity flaw CVE-2026-20349 in ASA and FTD SSL VPN services, allowing unauthenticated remote denial-of-service attacks.

Cisco released a security advisory addressing CVE-2026-20349, a high-severity vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD Software. Successful exploitation by an unauthenticated remote attacker can cause affected devices to crash or reload, causing denial of service. The vulnerability is being exploited in the wild, and patches are available; organizations with internet-exposed ASA/FTD VPN endpoints should prioritize updating.

Qualys ThreatPROTECT · Aug 13, 2026Exploit / PoC in the wildCVE-2026-20349

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

Cisco expanded an SSL VPN denial-of-service advisory to cover all ASA and FTD software platforms; unauthenticated attackers can exhaust device memory.

A vulnerability in the VPN and management web servers of Cisco ASA Software and Cisco Secure FTD Software allows an unauthenticated remote attacker to exhaust system memory or buffer blocks, causing a denial of service. Originally scoped to the ASAv and FTDv virtual appliances, Cisco updated the advisory on September 16, 2026 to cover all ASA and FTD platforms.

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

Cisco patches CVE-2026-20349, a high-severity unauthenticated DoS in ASA and FTD VPN services now added to CISA's KEV.

CVE-2026-20349 affects the Remote Access SSL VPN service in Cisco Secure Firewall ASA and FTD software, where specially crafted unauthenticated HTTP requests can cause appliances to reload, creating a denial of service. Cisco confirmed active exploitation observed in August 2026 and released hot fixes for ASA versions 9.16 through 9.24 and FTD versions 7.0 through 10.0. The flaw was added to CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of August 14, 2026 for US civilian federal agencies. No workarounds or indicators of compromise are available.

Help Net Security · Aug 13, 2026Exploit / PoC in the wildCVE-2026-20349

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability

Cisco patched a DTLS flaw in ASA and FTD software for Secure Firewall 3100/4200 series letting unauthenticated attackers trigger device reloads.

Improper resource management when processing DTLS messages in Cisco ASA and Secure Firewall Threat Defense software for Secure Firewall 3100 and 4200 series devices allows an unauthenticated remote attacker to cause a denial of service. Exploitation via a crafted stream of DTLS traffic causes the device to reload. Cisco has released software updates.

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

Cisco's September 2026 firewall hardening release fixes internally found ASA, FTD, and FMC flaws, two of which are actively exploited.

Cisco released September 2026 hardening updates for Secure Firewall ASA, FTD, and FMC software addressing multiple vulnerabilities discovered during a comprehensive internal security review. Two of the vulnerabilities are known to be actively exploited, including a Cisco Secure Firewall Management Center static credential vulnerability. Details are provided in separate linked advisories.

Cisco Security Advisories · 3h agoAdvisory in the wild 6 sources

Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability

Cisco fixed an SSL certificate parsing flaw in FTD's Snort 2 engine letting unauthenticated remote attackers force detection engine restarts.

Incomplete validation of SSL certificates in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense software allows an unauthenticated, remote attacker to send a crafted SSL connection setup request for parsing. A successful exploit restarts the Snort 2 Detection Engine unexpectedly, causing a denial of service. Cisco has released software updates, and no workarounds address the vulnerability.

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability

Cisco disclosed a TCP DNS flaw in ASA and FTD firewall software letting unauthenticated remote attackers trigger device reloads and denial of service.

A logic error in the DNS over TCP implementation of Cisco Secure Firewall ASA and FTD software mishandles buffer-size tracking when parsing DNS queries. An unauthenticated, remote attacker can send a crafted reply to a DNS query sent from the targeted device, causing the TCP DNS response handler to restart and the device to reload. The result is a denial of service condition on affected firewalls.

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities

Cisco patched ACL Object Group Search bypass flaws in ASA and FTD firewall software that let unauthenticated attackers reach protected networks.

Cisco disclosed multiple vulnerabilities in the ACL Object Group Search implementation of Secure Firewall ASA and FTD Software, caused by a logic error in populating group access control policies. An unauthenticated remote attacker could send traffic that should be blocked through the device, bypassing configured access controls. Cisco has released software updates; no exploitation is mentioned.

Cisco security advisory (AV26-197) – Update 3

CISA added Cisco CVE-2026-20079 to its KEV catalog; the Canadian Cyber Centre urges updates across Secure Firewall ASA, FTD, FMC, and SCC products.

The Canadian Centre for Cyber Security updated advisory AV26-197 covering March 2026 Cisco advisories for Security Cloud Control, Secure Firewall Management Center, ASA, and FTD. Cisco confirmed CVE-2026-20131 was actively exploited on March 18, 2026, and CISA added it to KEV on March 19. In Update 3, dated September 9, 2026, CISA added CVE-2026-20079 to the KEV catalog. The underlying flaws include FMC authentication bypass and remote code execution, ASA TCP-flood denial of service, and ASA/FTD IPsec denial of service.

Canadian Centre for Cyber Securityupdated · 2d agofirst · 6d agoExploit / PoC in the wild 11 sourcesCVE-2026-20131CVE-2026-20079

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

Cisco will publish security advisories with fixed software on September 16, 2026, covering BroadWorks, ISE, Nexus Dashboard, ASA, FMC, FTD and ThousandEyes.

Cisco PSIRT announced advance notification for security advisories to be published on September 16, 2026, along with fixed software releases. Affected products include BroadWorks CommPilot Application Software, Identity Services Engine (ISE), Nexus Dashboard, Secure Firewall ASA, Secure Firewall Management Center (FMC), Secure Firewall Threat Defense (FTD), and ThousandEyes Virtual Appliance. ISE, Nexus Dashboard and the Secure Firewall products receive security hardening releases, and the ASA, FMC and FTD advisories will be included in the same combined release.

Cisco Security Advisories · 7d agoAdvisory

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

Cisco patched an unauthenticated remote DoS in ASA and FTD Remote Access SSL VPN that reloads devices via crafted HTTP requests.

Cisco disclosed a denial-of-service vulnerability in the Remote Access SSL VPN service of Secure Firewall ASA and FTD software. Insufficient error checking when processing HTTP requests allows an unauthenticated, remote attacker to send a crafted HTTP request that causes the affected device to reload. Cisco has released software updates addressing the flaw.

Cisco Security Advisories · Aug 11, 2026Advisory

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog.

CISA adds three actively exploited flaws—Cisco ASA/FTD DoS, Windows Winsock SYSTEM-level UAF, and Metabase SQL injection—to its Known Exploited Vulnerabilities catalog.

CISA added CVE-2026-20349 (CVSS 8.6, heap inspection flaw crashing Cisco ASA/FTD via crafted HTTP requests to the Remote Access SSL VPN service), CVE-2026-68820 (CVSS 7.0, use-after-free in the Windows afd.sys Winsock driver allowing SYSTEM-privilege code execution, actively exploited per Microsoft) and CVE-2026-72898 (CVSS 10.0, unauthenticated SQL injection in Metabase) to the KEV catalog. Metabase disclosed its cloud service was attacked with the 0-day, giving the intruder a path to administrator rights and stored credentials for connected databases; cloud instances were patched while self-hosted deployments need urgent updates. Under BOD 22-01, federal civilian agencies must patch by August 14, 2026, except CVE-2026-68820, due August 25.