A High-Severity VPN Flaw in Cisco Software is Being Actively Exploited, Causing Devices to Crash
A critical vulnerability has been discovered in Cisco’s Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software, which is being exploited by attackers to remotely crash affected devices. The flaw, tracked as CVE-2026-20349, affects devices running certain remote access services, including IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD devices.
The vulnerability, which has a severity score of 8.6, is caused by insufficient error checking while processing HTTP requests. This allows an attacker to send a crafted HTTP request to the Remote Access SSL VPN service on an affected device, causing it to reload and resulting in a Denial-of-Service (DoS) condition. The vulnerability can be exploited remotely without authentication or user interaction when SSL listen sockets are enabled.
Cisco has released hot fixes for affected ASA and FTD software releases, including versions 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, as well as FTD releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. However, there are no workarounds for the vulnerability, and Cisco strongly recommends that customers upgrade to a fixed software release to fully remediate the issue.
It’s worth noting that this is not an isolated incident – Cisco has recently disclosed several other vulnerabilities in its products, including ClamAV flaws with public exploits and a static credential flaw exploited in zero-day attacks. The company’s advisory does not provide indicators of compromise associated with the ongoing exploitation, leaving customers to rely on the hot fixes released by Cisco.
The discovery of this vulnerability highlights the importance of regular security updates and patches for critical infrastructure software like firewalls. It also underscores the need for organizations to have robust incident response plans in place to quickly respond to potential attacks. As we continue to see an increase in high-severity vulnerabilities being actively exploited, it’s essential for customers to stay vigilant and prioritize patching and updating their systems to prevent these types of incidents.
In light of this vulnerability, we recommend that all organizations using Cisco Secure Firewall ASA or FTD software review the affected versions listed by Cisco and apply the necessary hot fixes as soon as possible. This will help prevent potential crashes caused by attackers exploiting the flaw, ensuring business continuity and protecting sensitive data.
Source: Bleeping Computer — 2026-08-11