Cisco ASA and FTD VPN Flaw Actively Exploited to Crash Devices

Cisco ASA and FTD VPN Flaw Actively Exploited to Crash Devices

First seen 11 Aug 2026, 20:56 UTC BleepingcomputerFeeds.4Sysops 86% similarity 72.8

Article Content

Browse articles
ThreatCluster

Cisco has issued a warning regarding a high-severity denial-of-service vulnerability, CVE-2026-20349, affecting Secure Firewall ASA and FTD devices. This flaw, with a CVSS score of 8.6, allows attackers to remotely crash devices by sending crafted HTTP requests to the Remote Access SSL VPN service. The vulnerability impacts devices with specific remote access services enabled and can be exploited without authentication. Cisco has confirmed that there are no workarounds available and strongly recommends upgrading to fixed software releases. Active exploitation was detected in August 2026, although details about the attackers or targeted organizations remain undisclosed. Cisco has released hot fixes for several affected software versions, but no indicators of compromise have been provided. The vulnerability was identified during internal security testing and reported by a researcher.

Key Points: • CVE-2026-20349 is a high-severity DoS vulnerability affecting Cisco ASA and FTD devices. • Attackers can exploit the flaw remotely without authentication, leading to device crashes. • Cisco has released hot fixes but no workarounds; active exploitation has been confirmed.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
CVE-2026-20349 published
Cisco disclosed a denial-of-service vulnerability affecting Secure Firewall ASA and FTD devices with a CVSS score of 8.6.
BleepingComputer
2026-08-11
Active exploitation confirmed
Cisco's PSIRT reported that CVE-2026-20349 is being actively exploited in attacks to crash devices.
BleepingComputer
2026-08-11
Hot fixes released
Cisco released hot fixes for affected ASA and FTD software versions to address the vulnerability.
BleepingComputer

Community

Browse all →

Tracked Entities in This Story