Cisco Firewall Vulnerability Allows Attackers to Restart Devices with Single Request
A critical vulnerability has been discovered in Cisco's Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) devices, allowing attackers to force them to restart with a single unauthenticated HTTP request. This vulnerability, tracked as CVE-2026-20349, was confirmed by Cisco in August 2026 and has already been actively exploited in the wild.
The flaw is located in the Remote Access SSL VPN service and can be triggered by sending a crafted HTTP request to an affected device. This causes the device to restart, resulting in downtime that affects all traffic passing through it, including public-facing web applications and APIs, not just remote access sessions.
Cisco has released fixed software for ASA versions 9.16-9.24 and FTD versions 7.0-10.0, which is the immediate mitigation available to affected organizations. In the long term, Cisco recommends reducing the attack surface by restricting access to the SSL VPN interface, mapping exposure by reviewing firewall configurations, and separating functions by splitting traffic handling across multiple devices.