Cisco Warns of High-Severity DoS Vulnerability in Secure Firewall ASA and FTD Software
Cisco has warned of a high-severity denial-of-service (DoS) vulnerability in its Secure Firewall ASA and Threat Defense (FTD) software. The flaw, tracked as CVE-2026-20349, allows an attacker to remotely crash affected devices by sending a crafted HTTP request to the Remote Access SSL VPN service.
The vulnerability has a severity score of 8.6 and impacts devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) software with certain remote access services enabled. It can be exploited remotely without authentication or user interaction when SSL listen sockets are enabled.
Cisco has released hot fixes for affected ASA and FTD releases, but there are no workarounds for the vulnerability. The company strongly recommends that customers upgrade to a fixed software release to fully remediate the issue.