Cisco confirms active exploitation of CVE-2026-20349 in ASA and FTD firewalls
Cisco has confirmed that attackers are actively exploiting CVE-2026-20349, a high-severity flaw (CVSS 8.6) in Secure Firewall ASA and FTD software. A single unauthenticated crafted HTTP request to the Remote Access SSL VPN service can crash the device. Cisco says there is no workaround; CISA ordered US federal agencies to patch by August 14.
Cisco has confirmed active exploitation of CVE-2026-20349, a high-severity (CVSS 8.6) vulnerability in Secure Firewall ASA and FTD software. Insufficient error checking in how the device processes HTTP requests to its Remote Access SSL VPN service lets an unauthenticated attacker force a reload with a single crafted request, no password or user interaction required. The flaw affects devices running IKEv2 remote access VPN, SSL VPN, or Zero Trust Network Access on FTD; Cisco's Firewall Management Center is not affected. Cisco found the issue during internal testing, and researcher Valerio Brussani reported it independently. Cisco has not disclosed who is behind the exploitation, its origin, or which organizations were hit. There is no workaround, only a hotfix or software upgrade. CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered US federal civilian agencies to patch by August 14, 2026.