High-Severity Vulnerability in Cisco Secure Firewall ASA and FTD
18 August 2026
Attackers are exploiting a vulnerability in Cisco Secure Firewall ASA and FTD to cause the affected device to reload unexpectedly, resulting in a denial of service condition. Patch immediately.
Background
Cisco has released security updates to address a high-severity vulnerability (CVE-2026-20349) affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software.
This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 8.6 out of 10.
Impact
Due to insufficient error checking when processing HTTP requests in the Remote Access SSL VPN service, an unauthenticated attacker could send a crafted HTTP request to cause the affected device to reload unexpectedly, resulting in a denial of service condition.
Known Exploitation
This vulnerability is being actively exploited in the wild.
Affected Products
This vulnerability affects Cisco Secure Firewall ASA and FTD Software when one of the following features is enabled:
IKEv2 Remote Access VPN with client services
SSL VPN
Zero Trust Network Access (FTD only)
The following software releases are affected:
Cisco Secure Firewall ASA releases: 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24
Cisco Secure Firewall FTD releases: 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
