CVE-2026-20349
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Aug 11, 2026
- US federal agencies must remediate it by Aug 14, 2026 (BOD 22-01)
- Attacked 1 day before the vulnerability was made public
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Source: CISA KEV · Sep 8, 2026 Aug 21, 2026 Aug 19, 2026 Aug 12, 2026 Aug 11, 2026 Aug 11, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| cisco | adaptive security appliance software | 9.16.1 |
| cisco | secure firewall threat defense | 7.0.0 |
Related articles
VulnerabilitiesCISA Adds Three Exploited Vulnerabilities to the KEV Catalog
CISA adds three exploited vulnerabilities to KEV catalog: CVEs in Cisco ASA/FTD, Windows, and Metabase. Organizations must prioritize remediation.
VulnerabilitiesCisco ASA and FTD: Actively Exploited Vulnerability Can Restart Firewalls
CVE-2026-20349 actively exploited: Cisco ASA/FTD vulnerability can restart firewalls causing DoS. Check affected versions and apply fixes.
VulnerabilitiesFour Critical Vulnerabilities Exploited Against macOS, SharePoint, VMware vCenter, and Windows
CISA has added four actively exploited critical vulnerabilities to its Known Exploited Vulnerabilities KEV catalog. The flaws affect Apple macOS,
VulnerabilitiesCisco Secure FMC Authentication Bypass Exploited for Root Access
Cisco confirms exploited CVE-2026-20079, a CVSS 10.0 FMC auth bypass allowing root access. See affected versions, hot fixes and log checks.
VulnerabilitiesCisco FMC Zero-Auth Flaws Exploited by Qilin Ransomware and Sandworm-Linked Hackers
Cisco FMC zero-auth flaws exploited by Qilin ransomware, Sandworm-linked hackers, and a third cluster for ransomware, credential theft, and espionage.
APTSandworm-Linked Operators Chain Cisco FMC Flaws to Deploy New Cyclops Blink
Russian-linked actors exploit CVE-2026-20079 and CVE-2026-20316 in Cisco FMC to deploy redesigned Cyclops Blink backdoor for persistence and espionage.
VulnerabilitiesCisco Fixes Critical ISE, FMC and Nexus Dashboard Flaws as Exploited Bugs Demand Immediate Action
Cisco patched critical ISE, FMC and Nexus Dashboard flaws, including exploited authentication bypass and root RCE bugs requiring urgent updates.
VulnerabilitiesAttackers Turn Network Management Consoles Into Gateways for Infrastructure-Wide Compromise
Attackers exploit Cisco FMC and ISE flaws for root access, credential theft and ransomware, turning consoles into infrastructure-wide gateways.
This product uses the NVD API but is not endorsed or certified by the NVD.