CVE-2026-20349: Actively Exploited Cisco ASA and FTD SSL VPN Denial-of-Service Flaw

Share:

Cisco has patched a flaw in the remote-access VPN service of its widely used ASA and FTD firewalls
that attackers are already exploiting. By sending a single crafted web request to an affected firewall, an
unauthenticated attacker on the internet can force the device to reboot, knocking remote-access VPN
and the traffic it protects offline. There is no workaround, so any organisation running these firewalls
with SSL VPN, IKEv2 remote-access, or Zero Trust access enabled should apply Cisco’s hot fix
immediately.

1. Vulnerability Details

CVE ID – CVE-2026-20349
CVSS SCORE 8.6
EXPLOIT STATUS Active exploitation confirmed. Cisco PSIRT became aware of in-the-wild exploitation in August Cisco released hot fixes and states there are no workarounds. Cisco Security Impact
Rating: High.

Cisco classifies this as CWE-244. The Remote Access SSL VPN service in Cisco Secure Firewall ASA and FTD Software does insufficient error checking when it processes HTTP requests. An unauthenticated, remote attacker can send a crafted HTTP request to the service and cause the device to reload, producing a denial-of-service condition. A device is affected only if it runs a vulnerable release and has a vulnerable configuration that opens the SSL listen sockets: SSL VPN (webvpn), IKEv2 remote-access VPN with client services, or Zero Trust Network Access (FTD only). Cisco Secure Firewall Management Center is not affected.

2. Affected Products

  • Cisco Secure Firewall ASA Software running a vulnerable release with an SSL listen socket enabled (SSL VPN webvpn, or IKEv2 remote-access VPN with client services). Fixed in ASA hot fixes 89.16.4.50 (9.16), 89.18.4.50(9.18), 9.20.4.235 (9.20), 9.22.3.191 (9.22), 9.23.1.211 (9.23), and 9.24.1.221 (9.24).
  • Cisco Secure Firewall Threat Defense (FTD) Software with the same VPN features, plus Zero Trust Network Access. Fixed in FTD hot fixes for releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 (for exampleCisco_FTD_Hotfix_HK-7.4.7.1-1 for7.4).
  • A device is vulnerable only if it runs an affected release and has one of the listed configurations. Cisco Secure Firewall Management Center (FMC) is not affected.

3. Exploitation and Affected Configurations

Cisco disclosed the flaw on 11 August 2026 and confirmed active exploitation the same month. It was found in internal testing and also reported by Valerio Brussani (@val_brux).

  • Active exploitation Attackers are exploiting the flaw in the wild to reload affected firewalls. No authentication or user interaction is required, and there is no workaround.
  • Vulnerable configurations Only devices with an internet-reachable Remote Access SSL VPN listen socket are exposed: SSL VPN (webvpn enable), IKEv2 remote-access VPN with client-services, or Zero Trust Network Access on FTD.

4. Recommendations

  1. Find all Cisco Secure Firewall ASA and FTD devices with Remote Access SSL VPN, IKEv2 remote-access with client services, or Zero Trust Network Access enabled, confirming the listen sockets with show running config.
  2. Apply the Cisco hot fix for your ASA or FTD release immediately, as there is no workaround; when installing an ASA hot fix numbered 89.x (the 9.16 and 9.18 branches), also upgrade ASDM to 7.24.1.374 so it recognises the new version format.
  3. Where feasible, restrict which networks can reach the Remote Access SSL VPN interface while you patch,since any unauthenticated host that can reach the service can trigger the crash.
  4. Monitor affected firewalls for unexpected reloads and VPN service outages, and alert on repeated crashes that may indicate exploitation attempts.

5. Sources

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert