Junglewise Threat Intelligence

CVE-2026-20349: Cisco Secure Firewall ASA and FTD denial of service in SSL VPN

CVE-2026-20349 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2026-08-11

Executive brief

Cisco Secure Firewall devices, which protect corporate networks and provide secure remote access, are vulnerable to a flaw that can cause them to crash and reboot. An attacker can trigger this remotely without any login credentials, leading to a total shutdown of VPN services and network protection. This vulnerability is currently being exploited in the wild, posing a significant risk to business continuity and secure remote operations.

Technical details

A vulnerability in the Remote Access SSL VPN service of Cisco ASA and FTD software stems from insufficient error checking when processing HTTP requests. An unauthenticated, remote attacker can exploit this by sending a crafted HTTP request to the affected device's VPN interface. This triggers a heap-related error (CWE-244), causing the device to reload unexpectedly and resulting in a denial of service. The vulnerability is confirmed to be exploited in the wild and carries a CVSS score of 8.6 due to its high availability impact and lack of authentication requirements.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1 through 9.19.1
  • Cisco Secure Firewall Threat Defense (FTD) Software All versions supporting Remote Access SSL VPN

Timeline

  • 2026-08-11: advisory: Initial disclosure by Cisco and NVD publication
  • 2026-08-11: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog
  • 2026-08-11: exploited: Confirmed active exploitation in the wild

Related threats