Published Security3 min read
Cisco Says a Crafted HTTP Request Is Already Reloading ASA and FTD VPN Boxes
CVE-2026-20349 is an unauthenticated denial of service in Cisco ASA and Secure FTD, rated CVSS 8.6, exploited in the wild, with no workaround.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Cisco warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild.
- The flaw is tracked as CVE-2026-20349 with a CVSS score of 8.6 and is a case of insufficient error checking when processing HTTP requests, allowing an unauthenticated, remote attacker to trigger a denial-of-service condition.
- Cisco said in a Tuesday advisory: "An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device... A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition."
- Cisco said there are no workarounds that address the flaw.
- Affected devices are those running a vulnerable version of ASA or FTD software with one or more of these configurations: IKEv2 Remote Access VPN with client services (crypto ikev2 enable <interface> client-services port <ports>), SSL-VPN (webvpn enable <interface>), or Zero Trust Network Access (zero-trust enable).
Compiled by The WatchSomething wrong?How this is made
Why it matters
Cisco has confirmed that CVE-2026-20349, an insufficient error checking flaw in how Secure Firewall ASA and Secure FTD software process HTTP requests, is being exploited in the wild to knock affected devices over [1][2]. The company says an unauthenticated remote attacker can send a crafted HTTP request to the Remote Access SSL VPN service and cause the device to reload, producing a denial of service [3]. That is not a breach, but on an appliance that terminates employee remote access it is the same thing as the service being gone.
The bug carries a CVSS score of 8.6 [2]. Cisco says there are no workarounds [4], which removes the usual stopgaps: there is no ACL tweak or feature toggle offered, and the exposed service is the one your users depend on.
Exposure is determined by configuration, not just version. Cisco lists three vulnerable configurations: IKEv2 remote access VPN with client services enabled, SSL-VPN via `webvpn enable`, and Zero Trust Network Access via `zero-trust enable` [5]. Note the mismatch worth reading twice: the exploit path Cisco describes is a request to the Remote Access SSL VPN service [3], while the vulnerable configuration list is broader than SSL-VPN alone [5]. Treat any of those three as in scope.
Fixes exist across six ASA trains, including 9.20.4.235, 9.22.3.191, 9.23.1.211 and 9.24.1.221 [6][7]. On the FTD side, remediation is delivered as hotfix bundles rather than full releases, spanning six trains from 7.0 through 10.0 [8][9]. The presence of a 7.0 hotfix is a useful signal about who Cisco expects to be running this in production [8].
Provenance of the finding is mixed. Cisco says it found the issue during internal security testing and separately credited Valerio Brussani with discovering and reporting it [10]. Cisco became aware of active exploitation earlier in the month [11]. There are no published details on the attacks, the actor, who was targeted, or whether any attempts succeeded [12], so the only thing defenders can act on is the advisory itself.
CISA has added the flaw to its Known Exploited Vulnerabilities catalog and set a remediation deadline of August 14, 2026 for Federal Civilian Executive Branch agencies [13]. That deadline lands in the same month Cisco says it learned of exploitation [14], which is the tell for how CISA reads the risk. Non-federal operators get no deadline and the same exposure.
Practical order of work: identify appliances with any of the three configurations enabled, confirm the running train against Cisco's fixed builds and hotfixes, and schedule the reload you choose rather than the one an attacker picks for you. Because the impact is a device reload [3], monitoring should include unexplained restarts of internet-facing ASA and FTD units, not just failed authentication patterns.
What to watch: whether the exploitation Cisco describes turns out to be opportunistic disruption or reconnaissance ahead of something with a worse impact, given that no attack details have been published [12]; whether Cisco's affected configuration list expands beyond the current three [5]; and whether the August 14 federal deadline slips, which would suggest patch or hotfix friction in the field [13].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Cisco warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild.
- [2]
The flaw is tracked as CVE-2026-20349 with a CVSS score of 8.6 and is a case of insufficient error checking when processing HTTP requests, allowing an unauthenticated, remote attacker to trigger a denial-of-service condition.
- [3]
Cisco said in a Tuesday advisory: "An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device... A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition."
- [5]
Affected devices are those running a vulnerable version of ASA or FTD software with one or more of these configurations: IKEv2 Remote Access VPN with client services (crypto ikev2 enable <interface> client-services port <ports>), SSL-VPN (webvpn enable <interface>), or Zero Trust Network Access (zero-trust enable).
- [7]
Fixed ASA builds listed include 9.20.4.235 for the 9.20 train, 9.22.3.191 for 9.22, 9.23.1.211 for 9.23 and 9.24.1.221 for 9.24; fixed builds are also listed for the 9.16 and 9.18 trains.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
Additional citations
- Cisco, via The Hacker News
- Cisco advisory, via The Hacker News
- Cisco advisory
- Cisco
- The Hacker News
- CISA, via The Hacker News



