Cisco Warns of High-Severity DoS Flaw in ASA and FTD Software
Cisco has disclosed a high-severity vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, tracked as CVE-2026-20349. This flaw allows an unauthenticated remote attacker to force an affected firewall to reload, resulting in a denial-of-service (DoS) condition.
The security issue is caused by insufficient error checking when processing specially crafted HTTP requests through the Remote Access SSL VPN service. No authentication or user interaction is required, making internet-facing VPN gateways particularly attractive targets for disruption.
Cisco has not disclosed when it discovered the vulnerability, but it became aware of active exploitation in August 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and ordered U.S. federal civilian agencies to remediate it by August 14, 2026.