Cisco Firewalls Under Attack: Hackers Exploit High-Severity Flaw
Cisco has announced that hackers are exploiting a high-severity flaw in its ASA and FTD firewalls, which can force vulnerable devices to restart remotely. The vulnerability, known as CVE-2026-20349, allows attackers to trigger a denial-of-service condition without requiring authentication.
The issue stems from insufficient error checking when affected software processes HTTP requests sent to the Remote Access SSL VPN service. A crafted request can trigger an unexpected reload and cause a denial of service.
Cisco has released fixed software to address the vulnerability, and administrators are advised to prioritize patching vulnerable devices. The company rates the flaw 8.6 out of 10 in terms of severity, with valid VPN credentials not required for exploitation.