BigTech CompaniesCybersecurityNewswireTechnologyWhat's Buzzing

Cisco patches DoS flaw exploited against its firewalls

Originally published on: August 14, 2026
▼ Summary

– Cisco confirmed active exploitation of CVE-2026-20349, a high-severity flaw targeting its firewall products to cause temporary service interruption.
– CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring US civilian federal agencies to remediate it by August 14, 2026.
– The flaw affects Remote Access SSL VPN services in Cisco ASA and FTD software, triggered by a crafted HTTP request that causes unexpected reloads and denial of service.
– Exploitation requires no authentication or user interaction, and Cisco has released hot fixes for specific ASA and FTD versions, with no workarounds or compromise indicators available.
– The vulnerability was discovered during Cisco internal testing and also reported by security researcher Valerio Brussani.

A serious denial-of-service vulnerability in Cisco firewall products is already being exploited in the wild, prompting an urgent federal remediation deadline. The flaw, tracked as CVE-2026-20349, has been added to the CISA Known Exploited Vulnerabilities catalog, requiring U.S. civilian federal agencies to patch their systems by August 14, 2026.

Cisco’s Product Security Incident Response Team (PSIRT) confirmed it became aware of active exploitation in August 2026, though specific attack details remain undisclosed. The company has not released indicators of compromise, and no workarounds are currently available.

The vulnerability impacts the Remote Access SSL VPN service across two product lines: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Specifically, affected features include IKEv2 Remote Access VPN (with client services), SSL VPN, and Zero Trust Network Access (ZTNA). Devices running vulnerable software versions with any of these features enabled, meaning SSL listen sockets are active, are at risk.

Attackers can exploit CVE-2026-20349 by sending a specially crafted HTTP request to the vulnerable service. This triggers an unexpected reload of the security appliance, creating a denial-of-service condition. Critically, exploitation requires no authentication and no user interaction, making the attack vector particularly dangerous for exposed systems.

Cisco has responded by issuing hot fixes for ASA software versions 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, as well as FTD software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. The company noted that the flaw was initially identified during internal security testing, with additional reporting from independent researcher Valerio Brussani.

Organizations running affected Cisco firewalls should prioritize applying the available hot fixes immediately. Given the absence of workarounds and the confirmed active exploitation, delaying remediation could leave critical network infrastructure exposed to disruptive attacks.

(Source: Help Net Security)

Topics

cisco firewall vulnerability 98% network security 95% denial of service 93% exploit activity 91% cisa advisory 90% security patching 88% remote access vpn 87% software hotfixes 85% federal compliance 84% http request attacks 83%