A high-severity vulnerability in Cisco’s Secure Firewall ASA and Threat Defense (FTD) software has been exploited to remotely crash affected devices, according to a warning from the company. This flaw, tracked as CVE-2026-20349, impacts devices running specific versions of these software packages with certain remote access services enabled.
The vulnerability allows an attacker to send a crafted HTTP request to the Remote Access SSL VPN service on an affected device, which can cause the device to reload and result in a denial-of-service condition. This can be done remotely without requiring authentication or user interaction, making it a particularly concerning issue. Vulnerable configurations include IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD devices.
Cisco’s security advisory explains that the vulnerability is caused by insufficient error checking while processing HTTP requests. This flaw has been given a severity score of 8.6, indicating its high potential impact. Cisco has released hot fixes for affected ASA and FTD releases, but there are no workarounds available to mitigate the issue.
The company’s Product Security Incident Response Team (PSIRT) became aware of active exploitation of CVE-2026-20349 in August 2026, although it has not shared further information about the attacks. The vulnerability was also discovered through Cisco’s internal security testing and independently reported by security researcher Valerio Brussani.
This warning serves as a reminder to organizations that use these software packages to prioritize patching and upgrading their systems as soon as possible. Failing to do so may leave them vulnerable to exploitation, which can have serious consequences for network availability and security. Cisco strongly recommends that customers upgrade to a fixed software release to fully remediate the issue.
It’s also worth noting that this is not an isolated incident – recent reports have highlighted vulnerabilities in other Cisco products, including Secure Endpoint Connector for Windows, Mac, and Linux. While patches are not yet available, organizations should remain vigilant and stay informed about these developments to ensure their security posture remains strong.
For those affected by this vulnerability, the key takeaway is to act quickly to patch and upgrade their systems. This will help prevent potential exploitation and minimize downtime in case of a successful attack. Regularly monitoring software updates and staying informed about known vulnerabilities can also go a long way in maintaining robust security defenses.
Source: Bleeping Computer — 2026-08-11