Cisco ASA and FTD Devices Hit by Active Exploitation of CVE-2026-20349
Cisco ASA and FTD devices are vulnerable to CVE-2026-20349, a high-severity vulnerability that allows an unauthenticated remote attacker to cause a reboot via a specially crafted HTTP request.
The vulnerability has a CVSS score of 8.6 and affects Remote Access SSL VPN when certain remote access services are active on the device.
Cisco confirms active exploitation of the vulnerability, which can disrupt remote VPN connections and leave corporate networks unprotected or disrupt critical connections for employees and partners.
Administrators should review VPN logs, unexpected reboots, and HTTP requests preceding outages to detect potential exploitation.