Cisco Secure Firewall ASA and FTD active DoS exploitation denial-of-service flaw (CVE-2026-20349)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-20349 is being actively exploited against Cisco Secure Firewall ASA and FTD software, enabling crafted HTTP requests to trigger a remote denial of service on devices with certain remote access services enabled. Cisco has released hot fixes for affected releases and says there is no workaround other than upgrading to a fixed version.
Related Happenings
Cisco SSL VPN and GlobalProtect credential-probing campaign
Campaign
H score32
First: 18.12.2025 06:10
Last: 18.12.2025 06:10
Sources 1
About this happening:
A coordinated credential-based campaign is now probing Cisco SSL VPN and Palo Alto Networks GlobalProtect portals at scale, raising the risk of unauthorized access att...
Cisco SSL VPN and GlobalProtect credential-probing campaign
CampaignAbout this happening: A coordinated credential-based campaign is now probing Cisco SSL VPN and Palo Alto Networks GlobalProtect portals at scale, raising the risk of unauthorized access att...
UAT-9686 Cisco AsyncOS exploitation and persistence campaign
Campaign
H score36
First: 17.12.2025 20:45
Last: 17.12.2025 20:45
Sources 1
About this happening:
The UAT-9686 campaign is actively exploiting CVE-2025-20393 on Cisco AsyncOS email appliances, giving attackers root command execution and a foothold for persisten...
UAT-9686 Cisco AsyncOS exploitation and persistence campaign
CampaignAbout this happening: The UAT-9686 campaign is actively exploiting CVE-2025-20393 on Cisco AsyncOS email appliances, giving attackers root command execution and a foothold for persisten...
Timeline
-
11.08.2026 22:45 2 articles · 2h ago
Cisco warns of active exploitation of CVE-2026-20349 in Secure Firewall ASA and FTD
Initial DisclosureCisco says CVE-2026-20349 is a high-severity denial-of-service flaw in Secure Firewall ASA and Secure Firewall Threat Defense (FTD) software that is being actively exploited to send crafted HTTP requests to the Remote Access SSL VPN service and remotely force affected devices to reload. The vulnerability can be exploited without authentication or user interaction when SSL listen sockets are enabled, affects certain remote access configurations including IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD devices, and does not affect Secure Firewall Management Center (FMC). Cisco has released hot fixes for affected ASA and FTD releases and says there are no workarounds, so customers should upgrade to a fixed software release.
Show sources
- Cisco warns of ASA and FTD VPN flaw exploited to crash devices — www.bleepingcomputer.com — 11.08.2026 22:45
- Cisco warns of ASA and FTD VPN flaw exploited to crash devices — www.bleepingcomputer.com — 11.08.2026 22:45