TL;DR
Cisco disclosed a Cisco ASA and FTD VPN vulnerability on August 11, 2026. Tracked as CVE-2026-20349 (CVSS 8.6), it lets an unauthenticated attacker crash the firewall remotely. Cisco confirms this flaw is already exploited in the wild.
- CVE: CVE-2026-20349
- CVSS: 8.6 (High · CVSSv3)
- Product: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Affected: 9.16.1, 9.16.1.28, 9.16.2, 9.16.2.3, 9.16.2.7, 9.16.2.11 (+191 more)
- Impact: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
- Status: Exploited in the wild
- Action: See vendor advisory
Why This Cisco Firewall Flaw Matters
Cisco ASA and FTD devices guard the network edge for many organizations. A crash there cuts remote access and can knock services offline. Because attackers need no login, exposure is high on internet-facing firewalls.
Cisco confirmed the threat directly. According to the advisory, “the Cisco Product Security Incident Response Team (PSIRT) became aware of active exploitation of this vulnerability.”
How the Attack Works
The bug sits in the Remote Access SSL VPN service. It stems from weak input validation on incoming web traffic. Cisco states the flaw “is due to insufficient error checking when processing HTTP requests.”
An attacker sends a crafted HTTP request to the VPN service. As a result, the device reloads and drops into a denial of service state. The advisory notes a successful exploit can “cause the affected device to reload, resulting in a DoS condition.”
Affected Versions
The vulnerability affects ASA and FTD software with a vulnerable VPN configuration enabled. That includes SSL VPN, IKEv2 remote access VPN with client services, or Zero Trust Network Access. Cisco confirmed that Secure Firewall Management Center software is not affected.
Patch and Mitigation Steps
Cisco has released hot fixes and software updates for this Cisco ASA and FTD VPN vulnerability. Importantly, the advisory warns “there are no workarounds that address this vulnerability.”
Upgrade to a fixed release right away. You can review the full fixed-version list in the official Cisco security advisory. Use the Cisco Software Checker to confirm your exact release.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.