Cisco Patches Zero-Day Firewall Vulnerability
Cisco has released patches for a zero-day vulnerability affecting its firewalls running Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. The security hole, tracked as CVE-2026-20349, is related to the processing of HTTP requests.
A remote, unauthenticated attacker can cause an appliance to reload and enter a denial-of-service (DoS) condition by sending a specially crafted HTTP request to the Remote Access SSL VPN service.
Cisco became aware of active exploitation in August 2026 and has urged customers to apply the available hotfixes as soon as possible. The company also warned that these types of vulnerabilities could allow threat actors to disrupt security appliances, potentially preventing them from detecting and blocking further malicious activity.