VYPR
kevPublished Aug 12, 2026· 1 source

Cisco ASA and FTD Vulnerability Exploited in the Wild, Leading to Denial-of-Service

Cisco has issued a warning about CVE-2026-20349, a critical vulnerability in its Secure Firewall ASA and FTD software that is being actively exploited in the wild to cause denial-of-service conditions.

Cisco has alerted customers to a critical vulnerability, identified as CVE-2026-20349, that affects its Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. This flaw, which carries a CVSS score of 8.6, has already been observed being exploited by threat actors in real-world attacks. The vulnerability stems from insufficient error checking within the HTTP request processing mechanism.

An unauthenticated, remote attacker can exploit this vulnerability by sending a specially crafted HTTP request to the affected device's Remote Access SSL VPN service. A successful exploitation attempt could force the targeted device to reload, thereby triggering a denial-of-service (DoS) condition and disrupting network connectivity. This could have significant implications for organizations relying on these Cisco devices for their network security infrastructure.

The vulnerability impacts devices running specific versions of Cisco Secure Firewall ASA Software or Cisco Secure FTD Software, provided that certain configurations are enabled. These configurations include IKEv2 Remote Access VPN with client services, SSL-VPN, or Zero Trust Network Access. Organizations using these features on vulnerable versions are at risk if the flaw is not addressed.

Cisco has detailed the affected versions, which include ASA versions 9.16.1 through 9.24.x, and FTD versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. For each affected version, Cisco has provided specific fixed versions or hotfix details, indicating the necessary patches or updates required to remediate the vulnerability. Applying these updates is crucial for mitigating the risk of exploitation.

Unfortunately, Cisco has stated that there are no workarounds available to mitigate this specific vulnerability. This underscores the urgency for affected organizations to apply the provided patches as soon as possible. Cisco became aware of the active exploitation of this flaw earlier in August 2026, and the vulnerability was discovered during internal security testing. Valerio Brussani is credited with independently discovering and reporting the vulnerability.

In response to the active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20349 to its Known Exploited Vulnerabilities (KEV) catalog. This addition mandates that Federal Civilian Executive Branch (FCEB) agencies must implement the necessary fixes by August 14, 2026, to protect their systems from potential attacks.

While Cisco has confirmed active exploitation, details regarding the specific nature of the attacks, the threat actors involved, their origins, and the extent of successful compromises remain unknown. This lack of information makes it challenging for defenders to proactively identify targeted campaigns, but the KEV listing and the nature of the vulnerability suggest a broad potential impact.

This incident highlights the ongoing threat posed by vulnerabilities in widely used network security appliances. Organizations must maintain vigilant patching practices and monitor security advisories from vendors like Cisco and agencies like CISA to stay ahead of emerging threats and protect their critical infrastructure.

Synthesized by Vypr AI