Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Cisco Warns of ASA and FTD VPN Flaw Actively Exploited to Crash Firewalls
Cisco Warns of ASA and FTD VPN Flaw Actively Exploited to Crash Firewalls
NEWS

Cisco Warns of ASA and FTD VPN Flaw Actively Exploited to Crash Firewalls

CVE-2026-20349 (CVSS 8.6) in Cisco ASA and FTD allows unauthenticated remote attackers to crash SSL VPN devices via crafted HTTP requests — no workaround exists.

Dylan H.

News Desk

August 12, 2026
4 min read

Cisco has confirmed that a high-severity denial-of-service vulnerability in its Secure Firewall ASA and Firepower Threat Defense (FTD) software is being actively exploited in the wild. The flaw, CVE-2026-20349 (CVSS 8.6), allows an unauthenticated remote attacker to crash affected firewall devices by sending specially crafted HTTP requests to the SSL VPN service — no credentials or prior access required.

Cisco's Product Security Incident Response Team (PSIRT) confirmed active exploitation in its August 2026 advisory, making this a priority patch for organizations running Cisco firewall infrastructure.

Vulnerability Details

The flaw stems from insufficient error checking in how the ASA and FTD software processes HTTP requests directed at the Remote Access SSL VPN service. A malformed request triggers an unhandled error condition that forces the device to reload — effectively taking the firewall offline.

Affected Configurations

The vulnerability is exploitable when any of the following features are enabled:

  • IKEv2 Remote Access VPN with client services
  • SSL VPN (AnyConnect/Secure Client)
  • Zero Trust Network Access (ZTNA) on FTD devices

If none of these features are enabled, the device is not vulnerable. However, in most enterprise deployments, at least one of these configurations is active.

Affected Versions

Cisco Secure Firewall ASA:

  • 9.16.x
  • 9.18.x
  • 9.20.x
  • 9.22.x
  • 9.23.x
  • 9.24.x

Cisco Firepower Threat Defense (FTD):

  • 7.0.x
  • 7.2.x
  • 7.4.x
  • 7.6.x
  • 7.7.x
  • 10.0.x

Not affected: Cisco Firepower Management Center (FMC) — the management console is not vulnerable.

Why This Is Serious

While a CVSS 8.6 denial-of-service vulnerability might seem less urgent than a code execution flaw, the operational context changes the calculus significantly:

  1. Firewalls are critical network chokepoints — Taking down an ASA or FTD device disrupts VPN access for potentially thousands of remote workers, creates gaps in network segmentation, and may open the perimeter to other attacks during the downtime.

  2. Active exploitation is confirmed — This is not a theoretical flaw. Cisco PSIRT has observed attackers actively exploiting it, indicating tooling exists and campaigns are underway.

  3. No workaround exists — Cisco's advisory is explicit: there are no configuration changes that mitigate the vulnerability. The only fix is upgrading to a patched software release.

  4. Unauthenticated attack vector — Any host with network access to the SSL VPN interface (typically internet-facing) can trigger the crash with no credentials.

Remediation

Patch

Upgrade to the patched software release corresponding to your ASA or FTD version. Cisco has released fixes for all affected versions. Consult the Cisco Security Advisory for the specific fixed release for your software track.

Operational Steps

  1. Identify exposed devices — Audit which ASA/FTD devices have SSL VPN, IKEv2 VPN, or ZTNA enabled and are internet-accessible.
  2. Prioritize internet-facing devices — These are directly exploitable without network pivoting.
  3. Stage patched images — Pre-download patched software before scheduling maintenance windows.
  4. Monitor for exploitation indicators — Check for unexpected device reloads or %ASA-1-505014 style reload reason logs.
  5. Schedule emergency maintenance if internet-facing devices are running affected versions.

Interim Risk Reduction (Not a Fix)

While there is no configuration workaround, organizations can reduce exposure by:

  • Implementing ACLs or firewall rules to restrict who can reach the SSL VPN interface from the internet (e.g., limit to known IP ranges if feasible)
  • Enabling rate limiting on the outside interface to slow down automated exploitation attempts
  • Placing affected devices behind an upstream load balancer or ADC that can filter malformed HTTP requests

These measures reduce the attack surface but do not patch the vulnerability.

Context: Cisco ASA Vulnerabilities in 2026

This is not the first Cisco firewall flaw exploited in attacks this year. In March 2026, the Interlock ransomware group exploited a zero-day in Cisco Firepower Management Center (CVE-2026-20131) to achieve initial access. The pattern of ransomware operators and nation-state actors targeting Cisco firewall infrastructure reflects the high value of these devices as network entry points.

Organizations that have not audited their Cisco perimeter device patching cadence should use this advisory as an impetus to review their firewall software versions across the estate.

Sources

  • BleepingComputer — Cisco Warns of ASA and FTD VPN Flaw
  • Cisco Security Advisory — CVE-2026-20349

Related

  • Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131
  • PicketLink SAML Authentication Bypass CVE-2026-10579
  • SAP Commerce Cloud Maximum Severity RCE CVE-2026-58231
#Cisco#CVE#Vulnerability#VPN#Firewall#Denial of Service

Related Articles

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

CISA has added a newly disclosed Cisco Secure Firewall Management Center zero-day to its Known Exploited Vulnerabilities catalog following confirmed in-the-wild exploitation. A separate static credentials issue further compounds the risk to enterprise firewall deployments.

4 min read

Mandiant Reveals How Cisco SD-WAN Zero-Day CVE-2026-20245 Gained Root Access

Mandiant's post-incident analysis exposes a sophisticated multi-stage attack chain that exploited CVE-2026-20245 to plant a hidden root account on Cisco...

3 min read

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect portals carrying a...

5 min read
Back to all News