Illustrative image generated with AI
Cisco ASA and FTD: Actively Exploited Vulnerability Can Restart Firewalls
CVE-2026-20349 actively exploited: Cisco ASA/FTD vulnerability can restart firewalls causing DoS. Check affected versions and apply fixes.
Text generated by artificial intelligence, published without human review. AI transparency
Remote Attack Against the VPN Service
Cisco is warning that CVE-2026-20349 is being actively exploited. The high-severity vulnerability has a CVSS score of 8.6.
The flaw is caused by insufficient error handling during HTTP request processing. An unauthenticated remote attacker can send a specially crafted request to the Remote Access SSL VPN service.
Successful exploitation can cause the device to restart and trigger a denial-of-service (DoS) condition. Potential impacts include disruption of remote access and network security functions.
Cisco detected the malicious activity at the beginning of the month. The vulnerability was identified during internal testing and was independently discovered by Valerio Brussani.
The attacker’s identity and origin, the targeted organizations, the techniques used, and the actual success of the operations remain unknown.
Affected Products and Configurations
The issue affects devices running vulnerable versions of:
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Secure Firewall Threat Defense (FTD) Software
Devices are exposed when at least one of the following configurations is enabled:
- IKEv2 Remote Access VPN with client services:
crypto ikev2 enable <interface_name> client-services port <port_numbers> - SSL VPN:
webvpn enable <interface_name> - Zero Trust Network Access:
zero-trust enable
Fixed ASA Versions
- ASA 9.16:
89.16.4.50 - ASA 9.18:
89.18.4.50 - ASA 9.20:
9.20.4.235 - ASA 9.22:
9.22.3.191 - ASA 9.23:
9.23.1.211 - ASA 9.24:
9.24.1.221
FTD Hotfixes
For FTD 7.0, the 7.0.9.1 branch is available with the following packages:
Cisco_FTD_Hotfix_GC-7.0.9.1-1.sh.REL.tarCisco_FTD_SSP_FP1K_Hotfix_GC-7.0.9.1-1.sh.REL.tarCisco_FTD_SSP_FP2K_Hotfix_GC-7.0.9.1-1.sh.REL.tarCisco_FTD_SSP_Hotfix_GC-7.0.9.1-1.sh.REL.tar
The corresponding packages for other branches are:
- FTD 7.2:
HM-7.2.11.1-2.sh.REL.tar - FTD 7.4:
HK-7.4.7.1-1.sh.REL.tar - FTD 7.6:
DD-7.6.4.1-2.sh.REL.tar - FTD 7.7:
AN-7.7.11.1-2.sh.REL.tar
These hotfixes are distributed in variants for the Cisco_FTD, SSP_FP1K, SSP_FP2K, SSP_FP3K, and SSP platforms, with additional availability for selected models, including Cisco_Secure_FW_TD_1200, 200, 4200, and 6100.
For FTD 10.0, the fixes are provided in the following packages:
Cisco_FTD_Hotfix_S-10.0.0.1-2.sh.REL.tarCisco_FTD_SSP_FP1K_Hotfix_S-10.0.0.1-2.sh.REL.tarCisco_FTD_SSP_FP3K_Hotfix_S-10.0.0.1-2.sh.REL.tarCisco_FTD_SSP_Hotfix_S-10.0.0.1-2.sh.REL.tarCisco_Secure_FW_TD_200_Hotfix_R-10.0.0.1-2.sh.REL.tarCisco_Secure_FW_TD_1200_Hotfix_S-10.0.0.1-2.sh.REL.tarCisco_Secure_FW_TD_4200_Hotfix_S-10.0.0.1-2.sh.REL.tarCisco_Secure_FW_TD_6100_Hotfix_S-10.0.0.1-2.sh.REL.tar
Priority Updates and Deadlines
Cisco states that no effective workarounds are available. Administrators should therefore install the fixed release or the hotfix corresponding to their deployed branch.
Priority should be given to devices exposing SSL VPN, IKEv2 Remote Access VPN, or Zero Trust Network Access to untrusted networks.
CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. U.S. federal civilian agencies (FCEB) must complete the required updates by August 14, 2026.
No specific indicators of compromise have been disclosed. However, an unexpected VPN appliance restart combined with anomalous HTTP requests should prompt a review of the logs and update status.
Sources
This article is an original reworking based on the sources below.
