Cisco Devices Under Active Exploitation of High-Severity Vulnerability
Cisco Secure Firewall ASA and FTD devices are under active exploitation of CVE-2026-20349, a high-severity vulnerability that allows an unauthenticated remote attacker to cause a reboot via a specially crafted HTTP request.
The vulnerability affects Remote Access SSL VPN when certain remote access services are active on the device. According to Cisco, there is no workaround and the recommended action is to upgrade to a patched version or apply the available patch. Backups and alternate administrative access are also required before making any changes.
The attack is remote and does not require prior authentication when there are active SSL listening ports. This increases the risk for devices that expose the VPN directly to the internet.
Cisco has released hotfixes or interim fixes for affected versions, including ASA branches 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, as well as FTD branches 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0.