CVE-2026-20349: Cisco Firewall Flaw Actively Exploited for DoS

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/3 · Reconnaissance

Attackers identify internet-facing Cisco ASA/FTD appliances with Remote Access SSL VPN enabled.

T1595 – Active Scanning T1590 – Gather Victim Network Information
  • Target: devices with an open SSL listen socket (WebVPN, IKEv2 Client Services or FTD ZTNA)
  • Affected ASA versions 9.16–9.24 and FTD 7.0–7.7 plus 10.0
  • Firewall/VPN gateway at the internet–corporate-network edge as attack surface
PHASE 2/3 · Initial Access / Exploitation

The attacker sends an unauthenticated, specially crafted HTTP request to the Remote Access SSL VPN service.

T1190 – Exploit Public-Facing Application
  • CVE-2026-20349, CVSS 8.6 (High), vector AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • Root cause: improper error handling during HTTP processing (CWE-244)
  • Unauthenticated, no user interaction, network-based, low complexity
  • No workaround available – hotfixes only
PHASE 3/3 · Impact

The appliance mishandles the request and unexpectedly reloads – resulting in denial of service.

T1499 – Endpoint Denial of Service T1499.004 – Application or System Exploitation
  • Primary damage: availability outage due to forced reload
  • No data theft, no authentication bypass (C:None, I:None, A:High)
  • VPN access drops and the network perimeter fails simultaneously
  • Active exploitation confirmed by Cisco PSIRT, CISA (KEV, 2026-08-11) and CCCS (AL26-018)
Short & clear answers
Frequently asked questions about this incident
Am I affected by CVE-2026-20349?
You are only affected if you run a Cisco Secure Firewall ASA or FTD on a vulnerable version AND have a relevant remote access feature enabled (IKEv2 Remote Access VPN with Client Services, SSL VPN/WebVPN, or – for FTD only – ZTNA). Vulnerable versions are ASA 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24, plus FTD 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. If you don't run a Cisco ASA or FTD firewall at all, this specific flaw does not directly affect you.
What do I need to do right now?
Because active exploitation is confirmed and there is no workaround, installing the correct Cisco hotfix is the key action. Updates are available via the Cisco Software Center (e.g. ASA 9.20.4.235 or FTD 7.4.7.1, depending on branch and platform). First inventory your devices, determine the running version using Cisco's Software Checker, and patch internet-facing systems as a priority.
How dangerous is this vulnerability really?
Cisco rates the flaw at CVSS 8.6 out of 10 (High). The impact is a denial of service: a single crafted HTTP request can force the firewall to reboot without any authentication, taking down both VPN access and the perimeter at the same time. As things stand it does not involve data theft – Cisco rates confidentiality and integrity as "None" and only availability as "High".
What should I do if I have no in-house IT and everything is outsourced?
Ask your hosting provider, managed service provider (MSP) and VPN vendor in writing whether any Cisco ASA or FTD instances with remote access VPN run in your environment. Have them confirm which software versions are running and whether patching has already been done. The key point is to know for certain whether you are affected – any uncertainty should be actively clarified.
How can I tell if my device has already been attacked?
Review firewall, VPN, syslog and monitoring data from early August 2026 onward for unexpected reboots, failover events, service interruptions and suspicious HTTP requests against the remote access service. Cisco has not published specific indicators of compromise (IOCs); unexplained reloads are therefore a reason to investigate but not proof on their own. Preserve relevant logs and crash dumps in a forensically sound manner.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.