Cisco warns of ASA, FTD VPN flaw used to crash devices

▼ Summary
– Cisco is warning that CVE-2026-20349, a high-severity denial-of-service vulnerability (score 8.6), is being actively exploited to remotely crash devices running Secure Firewall ASA or FTD software.
– The flaw stems from insufficient error checking in HTTP request processing, allowing unauthenticated attackers to send a crafted request to the Remote Access SSL VPN service and cause a device reload.
– Vulnerable configurations include IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD devices, while Secure Firewall Management Center (FMC) is not affected.
– Cisco has released hot fixes for affected ASA releases (9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and FTD releases (7.0, 7.2, 7.4, 7.6, 7.7, 10.0), with no workarounds available.
– Cisco detected active exploitation in August 2026, but has not shared attack details or indicators of compromise; the flaw was found during internal testing and independently reported by researcher Valerio Brussani.
Cisco has issued an urgent warning about a high-severity denial-of-service vulnerability in its Secure Firewall ASA and Threat Defense (FTD) software, noting that attackers are already exploiting the flaw remotely to crash affected devices.
The vulnerability, identified as CVE-2026-20349, carries a severity score of 8.6 and affects systems running Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) software where certain remote access services are enabled.
According to a security advisory released today, the root cause lies in insufficient error checking during the processing of HTTP requests. Cisco explains that an attacker could send a specially crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit would force the device to reload, creating a denial-of-service condition.
The flaw is remotely exploitable without any authentication or user interaction, provided SSL listen sockets are active. Affected configurations include IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD devices. Notably, Secure Firewall Management Center (FMC) software remains unaffected.
Cisco has already shipped hot fixes for ASA versions 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, along with FTD releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. No workarounds exist for this issue, so Cisco is strongly urging customers to upgrade to a patched release as the only way to fully resolve the problem.
Cisco’s PSIRT indicated it learned of active exploitation of CVE-2026-20349 in August 2026. However, the company has withheld further details about the attacks, such as the identity of the threat actors or which organizations have been targeted. The advisory also omits any indicators of compromise related to the ongoing campaign.
The vulnerability was uncovered during Cisco’s internal security testing and was also independently reported by security researcher Valerio Brussani.
This disclosure follows another Cisco announcement this month regarding vulnerabilities in ClamAV that affect Secure Endpoint Connector for Windows, Mac, and Linux. Those flaws have public exploits available, yet patches have not been released and are expected later this month.
(Source: BleepingComputer)
