Cisco published an urgent security advisory on August 11, 2026, regarding a actively exploited denial of service (DoS) vulnerability in its Secure Firewall ASA and Threat Defense (FTD) firewalls. The flaw, identified by the number CVE-2026-20349, has a CVSS score of 8.6 (high severity) and allows a remote attacker to cause critical equipment to reboot unexpectedly.
An exploitation without authentication or user interaction
According to the advisory published by Cisco's PSIRT (Product Security Incident Response Team), the vulnerability results from insufficient error checking when processing HTTP requests. An attacker can exploit it by sending a specially crafted HTTP request to the Remote Access SSL VPN service of an affected device.
“A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.” — Cisco PSIRT
The exploitation is remote, without authentication, and without user interaction, as long as the SSL listen sockets are enabled. Vulnerable configurations include:
- IKEv2 Remote Access VPN with client services
- SSL VPN
- Zero Trust Network Access (ZTNA) on FTD devices
The Secure Firewall Management Center (FMC) software is, however, not affected by this flaw.
Available fixes, no workaround
Cisco has released hot fixes for the following versions:
| Product | Fixed Versions |
|---|---|
| ASA | 9.16, 9.18, 9.20, 9.22, 9.23, 9.24 |
| FTD | 7.0, 7.2, 7.4, 7.6, 7.7, 10.0 |
There is no workaround for this vulnerability. Cisco strongly recommends that administrators apply the fixes as soon as possible on all exposed devices.
An internal and external discovery
The vulnerability was identified both during Cisco's internal security testing and by independent security researcher Valerio Brussani, who reported it to the vendor. However, Cisco has not provided any indicators of compromise (IoCs) associated with the active exploitation, nor specified what types of organizations were targeted or who is behind the attacks. The PSIRT simply states that it became aware of the active exploitation in August 2026.
A busy context for Cisco
This alert is part of a series of critical vulnerabilities affecting Cisco products during the year 2026:
-
CVE-2026-20316 (July 2026): a flaw due to static credentials in the Secure Firewall Management Center (FMC), actively exploited in zero-day attacks. The default identifier of a low-privilege account allowed for unauthorized access, which could be combined with other vulnerabilities for privilege escalation.
-
CVE-2026-20079 (March 2026, updated in July): a critical vulnerability (CVSS 10.0) that is bypassable for authentication in FMC, allowing an unauthenticated remote attacker to execute commands as root via specially crafted HTTP requests. Cisco has not confirmed any active exploitation to date, but the two FMC flaws share a common indicator of compromise (
/var/tmp/license.tmp), suggesting a possible link. -
CVE-2026-20230 (June 2026): an SSRF flaw in Cisco Unified Communications Manager, actively exploited and added to the CISA's KEV (Known Exploited Vulnerabilities) catalog. CISA had set a remediation deadline of only a few days for federal agencies.
-
CVE-2026-20337 and CVE-2026-20338 (August 2026): two ClamAV vulnerabilities in the Secure Endpoint Connector, with public proofs of concept available, although no active exploitation has been confirmed at this stage.
According to BleepingComputer, CISA has listed 95 Cisco vulnerabilities as actively exploited since November 2021, six of which have been used in ransomware attacks.
Recommendations for administrators
Given the absence of a workaround and active exploitation, security teams should:
- Inventory all devices running ASA or FTD with enabled remote access VPN services (SSL VPN, IKEv2 RA VPN, ZTNA).
- Check the exposure of VPN interfaces to the Internet — the attack surface is directly tied to the accessibility of the SSL VPN service.
- Apply the available hot fixes for the affected versions, prioritizing publicly exposed devices.
- Monitor for unexplained reboots of devices, which could indicate attempts at exploitation.
- Regularly consult Cisco's PSIRT portal for any updates to the advisory, including the addition of indicators of compromise.
Cisco specifies that ClamAV fixes for the Secure Endpoint Connector will be released later in August, meaning that some versions will remain vulnerable for several more days.
In conclusion
The CVE-2026-20349 flaw once again highlights the attractiveness of VPN and firewall infrastructures for attackers. Edge firewalls are prime targets: their compromise or unavailability can paralyze the remote access of an entire organization. The absence of a workaround and the active exploitation make this vulnerability an immediate remediation priority for any environment using Cisco Secure Firewall ASA or FTD with enabled VPN services.