Cisco's Secure Firewall Hit by Zero-Day Vulnerability CVE-2026-20349
Cisco's Secure Firewall ASA and FTD software has been hit by a zero-day vulnerability tracked as CVE-2026-20349. The flaw, which was confirmed to be actively exploited in August 2026, allows an unauthenticated remote attacker to crash the Remote Access SSL VPN service with a single crafted HTTP request.
The CVSS score for this vulnerability is 8.6, indicating a high severity level. Cisco's Product Security Incident Response Team became aware of active exploitation in late July 2026, and the company published its advisory and hot-fix releases on August 11, 2026.
A total of six ASA and FTD software versions are affected by this vulnerability, including ASA 9.16.4.50 and FTD hot-fix bundles across various branches. Cisco has stopped short of estimating the global device count, but security teams tracking the CISA KEV entry describe it as a priority-one item due to its reachability from the public internet.