Back to Blog
CVE-2026-20349: Cisco Secure Firewall — Remote DoS Zero-Day Exploited (August 2026)
vulnerabilities

CVE-2026-20349: Cisco Secure Firewall — Remote DoS Zero-Day Exploited (August 2026)

breachwire TeamAug 25, 20262 min read

CVE-2026-20349 — Cisco Secure Firewall

CVE-2026-20349 is a critical vulnerability in Cisco Secure Firewall ASA and FTD devices, allowing remote unauthenticated attackers to trigger denial-of-service by sending specially crafted HTTP requests to the Remote Access SSL VPN service. Cisco confirmed active exploitation in August 2026. The flaw is under urgent remediation, with CISA mandating immediate patching for federal agencies.

Attack Vector

Attackers exploit CVE-2026-20349 by sending maliciously crafted HTTP requests to the Remote Access SSL VPN interface exposed on vulnerable Cisco Secure Firewall ASA and FTD devices. No authentication is required. Successful exploitation forces the device to reload, causing a denial-of-service state and disrupting firewall operations. This can blind security monitoring and open the network to further attacks.

Who Is at Risk

All organizations running Cisco Secure Firewall ASA and FTD appliances with the Remote Access SSL VPN service enabled are at risk. Cisco has confirmed exploitation in the wild. The vulnerability affects deployments globally, with federal agencies specifically required to patch per CISA’s Known Exploited Vulnerabilities catalog.

Patch & Mitigate

  • Patch: Apply Cisco’s hotfixes for ASA and FTD immediately. Refer to Cisco’s official advisory for exact versions and patch details. Deadline for federal agencies is ASAP per CISA KEV.
  • Workaround: No official workaround is available. Disabling the Remote Access SSL VPN service may reduce exposure if patching is not immediately possible.
  • Detect: Review firewall and VPN logs for unexpected reloads or crash events, and monitor for anomalous HTTP requests targeting the SSL VPN interface.

MITRE ATT&CK

  • TA0040 — Impact: Attackers disrupt device availability, causing denial-of-service.
  • T1499 — Endpoint Denial of Service: The vulnerability is exploited to force device reboots, interrupting security functions.

Source: https://www.securityweek.com/cisco-patches-firewall-zero-day-exploited-for-dos-attacks/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: