Skip to content

Security1 publisher3 min readPublished

One packet reboots your Cisco VPN box, and Cisco will not say who is firing it

CVE-2026-20349 lets an unauthenticated attacker crash any ASA or FTD running Remote Access SSL VPN. There is no workaround, exploitation is confirmed, and attribution is a blank page.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying One packet reboots your Cisco VPN box, and Cisco will not say who is firing it
Photo: eclypsium.com

What happened

  • On August 11, 2026, Cisco published an advisory for CVE-2026-20349, scoring it as high with a CVSS 3.1 score of 8.6.
  • Cisco describes the vulnerability as insufficient error checking when processing HTTP requests, allowing an unauthenticated remote attacker to send a crafted HTTP request and trigger an unexpected device reboot. The flaw affects the Remote Access SSL VPN service on most ASA and FTD devices.
  • The entire attack can be executed in one packet and requires no credentials or user interaction.
  • CISA added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog on August 11, 2026, with a mandatory remediation deadline of August 14, 2026, giving US Federal Civilian Executive Branch agencies just three days to patch.
  • The KEV listing and the CISA remediation deadline fall on the same day the Cisco advisory was published and three days later respectively.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Cisco published an advisory on August 11, 2026 for CVE-2026-20349, a defect in the Remote Access SSL VPN service that lets an unauthenticated remote attacker force an unexpected reboot on Adaptive Security Appliance and Firepower Threat Defense devices with a single crafted HTTP request [1][2][3]. CISA added it to the Known Exploited Vulnerabilities catalog the same day with a remediation deadline of August 14, giving Federal Civilian Executive Branch agencies three days [4][5][15].

The mechanism is unglamorous: insufficient error checking when processing HTTP requests [2]. The consequences are not. The whole attack fits in one packet and needs no credentials and no user interaction [3], and the CVSS 3.1 vector reflects that: network-reachable, low complexity, no privileges required, no user interaction, scored 8.6 and rated high [6][1]. According to Eclypsium's writeup, the scope-change flag is set because crashing the appliance does not stop at the appliance, it cuts every session the device is managing [7]. No workarounds exist. Patching is the only fix [8].

The exposed configurations are the ones a remote access gateway almost certainly runs: IKEv2 Remote Access VPN with client services, SSL VPN (webvpn), or Zero Trust Network Access on FTD [9]. Cisco has released hotfixes for all affected release trains, with per-branch versions listed in advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF [10]. The flaw was found in Cisco's internal testing and reported independently by researcher Valerio Brussani [11]. So the remediation path is clear, and the maintenance window is the concentrator itself, which is the box nobody wants to reboot during business hours.

What operators do not get is any basis for scoping. Cisco's PSIRT says only that the team became aware of active exploitation in August 2026, and Eclypsium reports that is the complete public picture: no threat actor group, no targeted sectors, no indicators of compromise, no incident count, nothing on what the malicious requests look like or where they came from [12][13]. The KEV entry confirms exploitation is real and adds nothing on attribution or scope [14]. Eclypsium calls that level of opacity unusual for a confirmed in-the-wild disclosure at this severity [16], and the practical effect is that a defender cannot tell whether they are looking at targeted pressure or a scanner sweep. Eclypsium notes nation-state operators have worked this terrain before, with Volt Typhoon compromising Cisco ASA devices for persistent footholds in US critical infrastructure and Salt Typhoon tunneling through network edge devices for long-term collection [17], but the technical bar here is low enough that opportunistic criminal scanning fits equally well [18].

Treating this as a nuisance outage is the mistake. Eclypsium's reading is that a forced reboot clears in-memory state, flushes connection tables, and may leave logging incomplete or absent [19], which makes it useful cover as well as an end in itself: crash a hospital, utility, or financial institution's VPN gateway at the wrong moment and you remove remote workforce access, drop site-to-site tunnels, and can interrupt incident response [20].

Watch for Cisco or CISA releasing indicators, which would let teams check logs retroactively rather than assume. Until then, unexplained ASA and FTD reboots since early August deserve to be treated as suspicious rather than as flaky hardware, and the patch state of every internet-facing concentrator is the number worth having by end of week.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories