Skip to content
Tech News
← Back to articles

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

read original more articles
Why This Matters

The active exploitation of a critical vulnerability in Cisco's ASA and FTD devices highlights the ongoing risks of remote DoS attacks in network security. This underscores the importance for organizations to promptly update their firmware to mitigate potential disruptions and maintain network stability. As attackers target VPN services, securing remote access remains a top priority for the tech industry and consumers alike.

Key Takeaways

Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices.

The flaw, tracked as CVE-2026-20349, has a severity score of 8.6 and impacts devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) software with certain remote access services enabled.

In a security advisory published today, Cisco said the vulnerability is caused by insufficient error checking while processing HTTP requests.

"An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device," Cisco explains in the advisory.

"A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition."

The vulnerability can be exploited remotely without authentication or user interaction when SSL listen sockets are enabled.

Vulnerable configurations include IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD devices. Cisco says Secure Firewall Management Center (FMC) software is not affected.

Cisco has released hot fixes for affected ASA 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24 releases, as well as FTD releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0.

There are no workarounds for the vulnerability, and Cisco strongly recommends that customers upgrade to a fixed software release to fully remediate the issue.

Cisco's PSIRT says it became aware of active exploitation of CVE-2026-20349 in August 2026, but the company has not shared additional information about the attacks, including who is exploiting the vulnerability or what organizations are being targeted.

... continue reading