ZeroHour

Search: “Cisco Secure Firewall ASA”

17 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Cisco security advisory (AV26-197) – Update 3

CISA added Cisco CVE-2026-20079 to its KEV catalog; the Canadian Cyber Centre urges updates across Secure Firewall ASA, FTD, FMC, and SCC products.

The Canadian Centre for Cyber Security updated advisory AV26-197 covering March 2026 Cisco advisories for Security Cloud Control, Secure Firewall Management Center, ASA, and FTD. Cisco confirmed CVE-2026-20131 was actively exploited on March 18, 2026, and CISA added it to KEV on March 19. In Update 3, dated September 9, 2026, CISA added CVE-2026-20079 to the KEV catalog. The underlying flaws include FMC authentication bypass and remote code execution, ASA TCP-flood denial of service, and ASA/FTD IPsec denial of service.

Canadian Centre for Cyber Securityupdated · 2d agofirst · 6d agoExploit / PoC in the wild 14 sourcesCVE-2026-20131CVE-2026-20079

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

CISA added actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 (CVSS 9.8) to KEV; federal agencies must patch by September 17, 2026.

CISA added CVE-2026-76461 (CVSS 9.8), a critical zero-day in Cisco AsyncOS for Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities catalog. The flaw stems from insufficient validation in email parsing, letting an unauthenticated remote attacker send a crafted email with malicious SQL statements to achieve arbitrary command execution with root privileges. Cisco confirmed active exploitation in the wild, notes no workarounds exist, and recommends checking mail_logs for suspicious SQL statements like 'COPY.*TO PROGRAM' on every cluster device. Under BOD 22-01, FCEB agencies must remediate by September 17, 2026.

Security Affairs · 17h agoExploit / PoC in the wild 15 sourcesCVE-2026-76461

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

Cisco patched an unauthenticated remote DoS in ASA and FTD Remote Access SSL VPN that reloads devices via crafted HTTP requests.

Cisco disclosed a denial-of-service vulnerability in the Remote Access SSL VPN service of Secure Firewall ASA and FTD software. Insufficient error checking when processing HTTP requests allows an unauthenticated, remote attacker to send a crafted HTTP request that causes the affected device to reload. Cisco has released software updates addressing the flaw.

Cisco Security Advisories · Aug 11, 2026Advisory

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

Cisco patches CVE-2026-20349, a high-severity unauthenticated DoS in ASA and FTD VPN services now added to CISA's KEV.

CVE-2026-20349 affects the Remote Access SSL VPN service in Cisco Secure Firewall ASA and FTD software, where specially crafted unauthenticated HTTP requests can cause appliances to reload, creating a denial of service. Cisco confirmed active exploitation observed in August 2026 and released hot fixes for ASA versions 9.16 through 9.24 and FTD versions 7.0 through 10.0. The flaw was added to CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of August 14, 2026 for US civilian federal agencies. No workarounds or indicators of compromise are available.

Help Net Security · Aug 13, 2026Exploit / PoC in the wildCVE-2026-20349

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog.

CISA adds three actively exploited flaws—Cisco ASA/FTD DoS, Windows Winsock SYSTEM-level UAF, and Metabase SQL injection—to its Known Exploited Vulnerabilities catalog.

CISA added CVE-2026-20349 (CVSS 8.6, heap inspection flaw crashing Cisco ASA/FTD via crafted HTTP requests to the Remote Access SSL VPN service), CVE-2026-68820 (CVSS 7.0, use-after-free in the Windows afd.sys Winsock driver allowing SYSTEM-privilege code execution, actively exploited per Microsoft) and CVE-2026-72898 (CVSS 10.0, unauthenticated SQL injection in Metabase) to the KEV catalog. Metabase disclosed its cloud service was attacked with the 0-day, giving the intruder a path to administrator rights and stored credentials for connected databases; cloud instances were patched while self-hosted deployments need urgent updates. Under BOD 22-01, federal civilian agencies must patch by August 14, 2026, except CVE-2026-68820, due August 25.

Cisco ASA and FTD DoS Vulnerability Exploited in the Wild (CVE-2026-20349)

Cisco patched actively exploited high-severity flaw CVE-2026-20349 in ASA and FTD SSL VPN services, allowing unauthenticated remote denial-of-service attacks.

Cisco released a security advisory addressing CVE-2026-20349, a high-severity vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD Software. Successful exploitation by an unauthenticated remote attacker can cause affected devices to crash or reload, causing denial of service. The vulnerability is being exploited in the wild, and patches are available; organizations with internet-exposed ASA/FTD VPN endpoints should prioritize updating.

Qualys ThreatPROTECT · Aug 13, 2026Exploit / PoC in the wildCVE-2026-20349

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco warns actively exploited flaw CVE-2026-20349 lets unauthenticated attackers crash ASA and FTD firewalls via SSL VPN; CISA added it to KEV.

Cisco fixed CVE-2026-20349 (CVSS 8.6) in Secure Firewall ASA and FTD software, insufficient error checking in HTTP request processing that lets unauthenticated remote attackers force device reloads via crafted requests to the Remote Access SSL VPN service. Hotfixes cover ASA 9.16 through 9.24 and FTD 7.0 through 10.0, and there are no workarounds; Cisco confirmed active exploitation earlier in August but did not name the actor or targets. The flaw was found during internal security testing. CISA added it to the KEV catalog, requiring federal civilian agencies to patch by August 14, 2026.

The Hacker News · Aug 12, 2026Exploit / PoC in the wildCVE-2026-20349

August 2026 CVE Landscape

Insikt Group catalogs 73 high-impact August 2026 CVEs (43 Very Critical), including PaperCut, Zimbra, and Metabase flaws actively exploited or weaponized.

Recorded Future's Insikt Group identified 73 high-impact vulnerabilities in August 2026, 43 rated Very Critical, spanning 45 vendors with Microsoft accounting for roughly 11%. 31 vulnerabilities surfaced via CISA's KEV catalog, with others validated via open sources, vendor telemetry, and honeypot data. New Nuclei detection templates were released for CVE-2025-62593 (Ray), CVE-2026-72898 (Metabase), and CVE-2026-9198 (IBM Langflow). The report also highlights two AI-assisted operations: UAT-10147 exploited Zimbra, AjaxPro, Nacos, and Telerik servers before using DeepAudit and PentestGPT post-compromise, while a separate Chinese-speaking actor weaponized Hermes Agent and DeepSeek in a failed attempt.

Recorded Future · 8d agoVulnerability in the wildCVE-2025-62593CVE-2026-72898CVE-2026-9198+4 CVEs

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Cisco warns of static low-privileged credentials in Secure Firewall Management Center's web interface, letting unauthenticated remote attackers log in and access sensitive data.

Cisco disclosed a vulnerability in the web interface of Secure Firewall Management Center (FMC) Software caused by the presence of static credentials for a low-privileged account. An unauthenticated remote attacker could log in to an affected device using the static account and access sensitive data within impacted systems. The attack surface is reduced when the FMC management interface does not have public internet access.

Cisco Security Advisories · Aug 11, 2026Advisory

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco patches nine Crosswork and Secure Workload flaws, five rated CVSS 10.0, found internally with no exploitation observed.

Cisco released fixes for four Crosswork platform vulnerabilities including CVE-2026-20030 SQL injection and CVE-2026-20357 missing authentication, both scoring CVSS 10.0, affecting Crosswork Release 7.2.1 and earlier. Five additional flaws in Secure Workload, including CVE-2026-20315 and CVE-2026-20317 at CVSS 10.0, affect SaaS and on-premises deployments up to releases 3.10 and 4.0. All issues were found through internal testing and are not known to be actively exploited. The patches follow a broader internal security review that recently addressed 12 Catalyst SD-WAN and IOS XE bugs.

September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows

Microsoft's September 2026 Patch Tuesday ships 964 fixes including two exploited Windows zero-days (CVE-2026-85880, CVE-2026-81963) and a wormable DNS RCE.

Microsoft's September 2026 Patch Tuesday includes 964 Microsoft vulnerabilities requiring customer action, a record attributed to AI-assisted bug discovery, plus 174 third-party/open-source and 23 Chromium/Edge CVEs. Two zero-days are exploited in the wild: CVE-2026-85880, a Windows ALPC heap overflow enabling AppContainer sandbox escape and privilege escalation, and CVE-2026-81963, a Windows Update Stack escalation to SYSTEM. CVE-2026-69730, an unauthenticated Windows DNS RCE, is not yet exploited but Microsoft expects exploitation, and roughly 20 bugs could be wormable. Separately, SAP issued a critical CVSS 10.0 fix for the EPP component used in S/4HANA and NetWeaver.

CSO Online · 7d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-69730+2 CVEs1

China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks

Sygnia links the China-nexus Fire Ant campaign to UNC3886, showing hackers weaponized compromised Cisco IOS XR routers for espionage and wider intrusions.

Sygnia's Fire Ant report details Chinese hackers compromising Cisco IOS XR routers, TACACS+ authentication servers and management infrastructure to capture traffic, harvest credentials and stage attacks on high-value and critical infrastructure networks. The group, which overlaps with Mandiant's UNC3886, developed custom router malware for persistence, hid logs, deleted files and tampered with firewall rules, and remained active in 2026 after Sygnia's 2025 disclosure. The activity aligns with prior Chinese campaigns against Cisco devices, including Volt Typhoon and Salt Typhoon operations.

The Record · 14d agoThreat actor

ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability

ZDI discloses CVE-2026-20316, a 9.8-rated unauthenticated authentication bypass in Cisco Secure Firewall Management Center login.cgi.

ZDI-26-533 describes an authentication bypass vulnerability in Cisco Secure Firewall Management Center's login.cgi that allows remote attackers to bypass authentication without any credentials. ZDI assigned a CVSS score of 9.8, and the flaw is tracked as CVE-2026-20316. As a central management plane for firewall infrastructure, compromise could enable broad policy changes.

ZDI Published Advisories · Aug 11, 2026VulnerabilityCVE-2026-20316

U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

CISA added actively exploited Cisco FMC, Chrome V8, Fortinet and Citrix NetScaler flaws to its KEV catalog, ordering federal patching by September 12.

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. CVE-2026-20079 (CVSS 10.0) is an unauthenticated authentication bypass in Cisco Secure Firewall Management Center's web interface enabling script execution and potential root access. CVE-2026-87491 (CVSS 8.8) is an out-of-bounds write in Chrome's V8 engine — the seventh actively exploited Chrome zero-day of 2026 — fixed in Chrome 153.0.8010.36. CVE-2025-25249 (CVSS 8.1) is a heap-based buffer overflow in FortiOS/FortiSwitchManager's cw_acd daemon being exploited with the PivotC2 RAT, and CVE-2026-19490 (CVSS 9.3) is a NetScaler SAML HTTP-Redirect authentication bypass; federal agencies must patch by September 12, 2026.

Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability

Cisco fixed a stored cross-site scripting flaw in Industrial Ethernet 1000 series switches exploitable by authenticated remote users.

Insufficient validation of user-supplied input in the web-based management interface of Cisco Industrial Ethernet 1000 Series Switches allows stored XSS. An authenticated remote attacker can inject malicious code into specific interface pages and execute arbitrary script in another user's context. Exploitation requires valid credentials; Cisco has released software updates.

Cisco Security Advisories · 27d agoAdvisory

CISA Warns of SonicWall SMA1000 Vulnerabilities Active Exploitation (CVE-2026-83548 & CVE-2026-83549)

CISA added two actively exploited SonicWall SMA1000 flaws to KEV: pre-auth SSRF CVE-2026-83548 (CVSS 10) and post-auth RCE CVE-2026-83549; patch by September 5.

CISA added CVE-2026-83548 and CVE-2026-83549 to the Known Exploited Vulnerabilities Catalog with a September 5, 2026 patch deadline. CVE-2026-83548 is a critical (CVSS 10.0) pre-authentication SSRF in the SMA1000 Appliance Work Place interface; CVE-2026-83549 is a high (CVSS 7.8) post-authentication OS command injection leading to RCE in the Appliance Management Console. SMA1000 models 6210, 7210, and 8200v running 12.4.3-03453 or 12.5.0-02835 platform-hotfix and older are affected; fixes ship in 12.4.3-03526 and 12.5.0-02952. Qualys customers can detect vulnerable assets via QID 388624.

Qualys ThreatPROTECT · 13d agoExploit / PoC in the wildCVE-2026-83548CVE-2026-83549