Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Cisco ASA and FTD CVE-2026-20349 Exploited
Aug 12, 2026
6 Mins Read
Moon
Summarize with:

Cisco ASA and FTD CVE-2026-20349 Exploited

Cisco has confirmed active exploitation of CVE-2026-20349, a High-severity denial-of-service (DoS) vulnerability affecting the Remote Access SSL VPN service in Cisco Secure Firewall ASA and Secure Firewall Threat Defense (FTD) Software.

The flaw allows an unauthenticated remote attacker to send a crafted HTTP request to an affected remote-access service and cause the device to reload. For organizations that rely on Cisco ASA or FTD for VPN access, firewall availability, or perimeter connectivity, this should be treated as an urgent patching priority.

What Is CVE-2026-20349?

CVE-2026-20349 (CVSS 8.6) is a vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software.

The vulnerability is remotely exploitable before authentication when a device exposes an affected remote access service. Cisco says the issue is caused by insufficient error checking while processing HTTP requests. In practice, a malformed request can trigger an unexpected reload, causing a denial-of-service condition.

Details of CVE-2026-20349 (SOCRadar Vulnerability Intelligence)

Details of CVE-2026-20349 (SOCRadar Vulnerability Intelligence)

Cisco maps the flaw to CWE-244, improper clearing of heap memory. The documented impact is availability loss. Cisco’s advisory does not describe arbitrary code execution, unauthorized VPN access, credential theft, data disclosure, privilege escalation, or persistence as part of CVE-2026-20349.

Which Cisco ASA and FTD Configurations Are Affected?

A device is affected when it runs a vulnerable ASA or FTD release and has one or more configurations that enable SSL listen sockets. Cisco lists the following potentially vulnerable configurations:

Feature Basic configuration indicator
IKEv2 Remote Access VPN with client services crypto ikev2 enable <interface_name> client-services port <port_numbers>
SSL VPN webvpn / enable <interface_name>
Zero Trust Network Access zero-trust / enable

Cisco notes that Zero Trust Network Access applies only to Cisco Secure FTD Software. Cisco Secure Firewall Management Center (FMC) Software is not affected.

Which Cisco ASA and FTD Versions Are Fixed?

Cisco does not provide one universal fixed version for every deployment. Administrators should verify the installed release and use Cisco’s advisory and Software Checker to identify the correct hot fix or fixed release.

For Cisco Secure Firewall ASA Software, Cisco lists the following hot fixes:

ASA release train Hot fix
9.16 89.16.4.50
9.18 89.18.4.50
9.20 9.20.4.235
9.22 9.22.3.191
9.23 9.23.1.211
9.24 9.24.1.221

For ASA 9.16 and 9.18 hot fixes beginning with 89, Cisco says administrators must install ASDM Release 7.24.1.374, because earlier ASDM versions do not recognize that ASA release-numbering format.

For Cisco Secure FTD Software, Cisco lists hot fixes across the 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 release trains. Administrators should match the exact platform and release train to Cisco’s fixed software guidance before upgrading.

How Could CVE-2026-20349 Be Exploited?

At a high level, an attacker sends a crafted HTTP request to the affected Remote Access SSL VPN service. If the target device is running a vulnerable release and exposes a vulnerable configuration, the request can cause the ASA or FTD device to reload.

The exploitation requirements are straightforward:

  • A vulnerable Cisco ASA or FTD software release
  • An enabled affected remote-access configuration
  • Network reachability to the service
  • No attacker authentication
  • No user interaction

This makes public-facing VPN and remote-access deployments the highest priority. A reload may be temporary, but the operational impact can be significant where the affected device supports business-critical VPN connectivity, perimeter access, or remote users.

Is CVE-2026-20349 Actively Exploited?

Yes. Cisco PSIRT says it became aware of active exploitation of CVE-2026-20349 in August 2026. Cisco strongly recommends that customers upgrade to a fixed software release.

Cisco has not publicly attributed the activity to a specific threat actor, campaign, target sector, or geography. The advisory also does not provide attacker IP addresses, payloads, hashes, user-agent strings, or a unique log signature.

Cisco lists Snort rules 46897 and 59654 as action links for this advisory. These rules can support detection, but they should not be treated as a replacement for patching.

Why Is This Cisco VPN Vulnerability Urgent?

CVE-2026-20349 should be prioritized because it combines confirmed exploitation with a perimeter-facing attack surface. Remote Access SSL VPN services are often internet-reachable by design, and Cisco’s CVSS vector shows no authentication or user interaction requirement.

The impact is denial of service, not confirmed device compromise. Still, availability matters for VPN concentrators and firewall infrastructure. A forced reload can interrupt remote access, disrupt sessions, affect protected services, and create operational pressure during active attack attempts.

Risk is highest where:

  • ASA or FTD remote-access services are internet-facing
  • SSL VPN, IKEv2 client services, or FTD ZTNA is enabled
  • The device lacks rapid failover
  • The device supports critical remote access or perimeter traffic
  • Logs show unexpected reloads or repeated malformed requests

How Can SOCRadar Help Prioritize Response?

SOCRadar’s Cyber Threat Intelligence module helps security teams track critical CVEs, exploit alerts, affected technologies, and changing exploitation signals. For CVE-2026-20349, this context can help teams monitor whether exploitation expands, whether new detection details emerge, and how remediation urgency changes over time.

SOCRadar’s Vulnerability Intelligence

SOCRadar’s Vulnerability Intelligence

The Attack Surface Management (ASM) module adds exposure context by identifying externally reachable assets, vulnerable software, exposed services, DNS records, and public-facing infrastructure. For this Cisco vulnerability, ASM can help teams prioritize ASA and FTD devices that expose affected VPN or ZTNA services to untrusted networks.

Together, vulnerability intelligence and exposure visibility help teams move from a broad Cisco alert to a focused remediation queue based on reachability, software version, business role, and failover status.

What Should Defenders Do Now?

1. Apply Cisco Fixes

Inventory all ASA and FTD devices, record software versions, and use Cisco’s Software Checker to identify the applicable hot fix or fixed release. Prioritize internet-facing devices that provide business-critical VPN access or lack rapid failover. Cisco states that there are no workarounds that address CVE-2026-20349.

2. Reduce Exposure While Patching

Where immediate patching is delayed, reduce unnecessary internet exposure and restrict access to remote-access listeners where operationally feasible. These controls may reduce risk, but they do not correct the vulnerability.

3. Validate Vulnerable Configurations

Confirm whether each device has SSL VPN, IKEv2 Remote Access VPN with client services, or FTD ZTNA enabled. Devices running vulnerable software with reachable SSL listen sockets should move to the front of the remediation queue.

4. Hunt for Unexpected Reloads

Review ASA and FTD logs for reloads, crashes, watchdog events, or abnormal restarts beginning in August 2026. Correlate those events with inbound HTTP or VPN-service traffic, unusual request bursts, repeated requests from single sources, and activity targeting internet-facing listeners.

5. Enable Defensive Detection

Verify that Snort rules 46897 and 59654 are current, enabled, and deployed where they can inspect traffic reaching affected services. Use detection as additional coverage while patching and validating exposure.