Published on August 13, 2026
[CVE-2026-20349] Cisco Releases Security Updates for Actively Exploited Secure Firewall Remote Access SSL VPN DoS Vulnerability
Severity
High
Detail
Cisco has released security updates to address a high-severity vulnerability, tracked as CVE-2026-20349, affecting the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. The vulnerability has a CVSS score of 8.6 (High Severity) and can allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial-of-service (DoS) condition.
The vulnerability is caused by insufficient error checking when processing HTTP requests. An attacker can exploit the issue by sending a specially crafted HTTP request to the Remote Access SSL VPN service. Successful exploitation could cause the affected security appliance to reload unexpectedly and temporarily interrupt its operation.
The vulnerability can be exploited without authentication and without requiring any user interaction. Cisco’s Product Security Incident Response Team (PSIRT) became aware of active exploitation in August 2026, while details regarding the attacks remain limited. The vulnerability has also been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
| CVE ID | Summary | CVSS Score |
| CVE-2026-20349 | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall ASA and FTD Software could allow an unauthenticated, remote attacker to cause the affected device to reload unexpectedly, resulting in a denial-of-service condition. | 8.6 (High) |
Affected Products
The vulnerability affects Cisco devices running vulnerable versions of Cisco Secure Firewall ASA Software or Cisco Secure Firewall FTD Software when one or more vulnerable features are enabled. The affected features include:
- IKEv2 Remote Access VPN with client services
- SSL VPN
- Zero Trust Network Access (ZTNA) – available only in Cisco Secure FTD Software
The vulnerability is present when the relevant configuration enables the SSL listen sockets. Cisco confirmed that Cisco Secure Firewall Management Center (FMC) Software is not affected.
Recommendation
Cisco strongly recommends that customers upgrade affected Cisco Secure Firewall ASA and FTD Software to the available fixed releases or install the applicable hot fixes. There are no workarounds that address this vulnerability.
Cisco has released hot fixes covering the following ASA software releases:
- ASA 9.16 — Hot Fix 89.16.4.50
- ASA 9.18 — Hot Fix 89.18.4.50
- ASA 9.20 — Hot Fix 9.20.4.235
- ASA 9.22 — Hot Fix 9.22.3.191
- ASA 9.23 — Hot Fix 9.23.1.211
- ASA 9.24 — Hot Fix 9.24.1.221
For FTD, hot fixes are available for releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Customers should refer to Cisco’s security advisory and Software Checker to determine the appropriate fix for their deployed version.
Source
https://www.helpnetsecurity.com/2026/08/13/cve-2026-20349-cisco-firewalls-dos/
https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF
https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html
