Published Security3 min read
Cisco firewall DoS bug is under active attack, and the federal fix deadline is August 14
CVE-2026-20349 reloads ASA and FTD appliances with a single unauthenticated HTTP request. Cisco lists no workarounds, and CISA wants it remediated by August 14, 2026.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Cisco confirmed that a high-severity vulnerability, CVE-2026-20349, is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls.
- CVE-2026-20349 has been added to CISA's Known Exploited Vulnerabilities catalog and must be remediated by US civilian federal agencies by August 14, 2026.
- Details about the attacks are currently under wraps; Cisco shared only that its Product Security Incident Response Team (PSIRT) became aware of active exploitation of the vulnerability in August 2026.
- CVE-2026-20349 affects the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software.
- The affected features are IKEv2 Remote Access VPN (with client services), SSL VPN, and Zero Trust Network Access (ZTNA).
Compiled by The WatchSomething wrong?How this is made
Why it matters
Cisco has confirmed that attackers are exploiting a high-severity flaw, CVE-2026-20349, to temporarily interrupt the operation of its firewalls [1]. The bug is in CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of August 14, 2026 for US civilian federal agencies [2], one day after Help Net Security reported the fixes [12][14].
The mechanics are as simple as this class of bug gets. A specially crafted HTTP request to the vulnerable service can cause the appliance to reload unexpectedly, producing a denial of service [7]. No authentication is required, and no user has to be tricked into clicking anything [8]. That combination means the only real precondition is reachability, and the affected service is one that organisations deliberately expose to the internet.
The exposed surface is the Remote Access SSL VPN service on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software [4]. Three features carry the risk: IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access [5]. An appliance is vulnerable only if it runs an affected software version and has one of those features enabled, meaning the SSL listen sockets are active [6]. That condition is worth reading closely, because Cisco offers no workarounds [10]. The only levers available are the hot fix or turning off remote access, and turning off remote access is the same outcome the attacker is trying to produce.
Cisco has issued hot fixes covering ASA versions 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24, and FTD versions 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 [9]. That is twelve separate software trains [13], which tells you something about the installed base this touches: not a narrow slice of current deployments but most of the fleet anyone has been running for the past several years.
Detection is the weak spot. Cisco published no specific indicators of compromise [10], and details of the attacks remain undisclosed; the company said only that its Product Security Incident Response Team became aware of active exploitation in August 2026 [3]. In practice, the artefact available to a defender is the symptom itself, an unexplained reload of the appliance [7]. Anyone who has written off a mystery VPN restart in the past two weeks as a firmware hiccup should go back and look at it again.
One detail in the advisory is worth noting for how these things surface. Cisco says it found the vulnerability during internal security testing, and that it was also reported by security researcher Valerio Brussani [11]. An internally discovered bug still ended up in the KEV catalog within days of the fix, which is the pattern to plan around: the gap between disclosure and a federal deadline is now measured in days, not quarters.
What to watch: whether Cisco updates the advisory with exploitation detail or indicators now that hot fixes are out, and whether the same crafted-request path proves to do more than reload the box. Denial of service on a VPN head-end is the reported impact today [1][7], but memory-corruption bugs in this service historically get revisited. Operators should also confirm which of the three features are actually enabled on each appliance [5][6], because that inventory is the difference between a patch window and a fire drill.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Cisco confirmed that a high-severity vulnerability, CVE-2026-20349, is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls.
- [2]
CVE-2026-20349 has been added to CISA's Known Exploited Vulnerabilities catalog and must be remediated by US civilian federal agencies by August 14, 2026.
- [3]
Details about the attacks are currently under wraps; Cisco shared only that its Product Security Incident Response Team (PSIRT) became aware of active exploitation of the vulnerability in August 2026.
- [4]
CVE-2026-20349 affects the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software.
ReportedView cited source - [5]
The affected features are IKEv2 Remote Access VPN (with client services), SSL VPN, and Zero Trust Network Access (ZTNA).
ReportedView cited source - [6]
An appliance is vulnerable if it runs an affected software version and one of the affected features is enabled, that is, if the SSL listen sockets are active.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- helpnetsecurity.comZeljka ZorzAug 13Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
Additional citations
- Help Net Security, reporting Cisco's confirmation
- Help Net Security
- Cisco security advisory, via Help Net Security



