Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Cisco has issued an alert about a critical vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. The flaw, identified as CVE-2026-20349 with a CVSS score of 8.6, allows unauthenticated attackers to trigger a denial-of-service condition by sending crafted HTTP requests to the Remote Access SSL VPN service.
The vulnerability impacts devices running vulnerable versions of ASA and FTD software, including ASA 9.161, ASA 9.181, and various versions of FTD from 7.0 to 10.0. Cisco has released fixes for these affected versions, which can be downloaded from its website.
Cisco became aware of the vulnerability earlier this month and credited Valerio Brussani for discovering and reporting it separately. The US Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply the fixes by August 14, 2026.