Full Report
Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger
Analysis Summary
# Vulnerability: Cisco ASA and FTD Remote Denial-of-Service (DoS)
## CVE Details
- **CVE ID:** CVE-2026-20349
- **CVSS Score:** 8.6 (High)
- **CWE:** Insufficient error checking when processing HTTP requests
## Affected Systems
- **Products:**
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Secure Firewall Threat Defense (FTD) Software
- **Versions:**
- **ASA:** 9.16.1, 9.18.1, 9.20, 9.22, 9.23, 9.24
- **FTD:** 7.0, 7.2, 7.4, 7.6, 7.7, 10.0
- **Configurations:** Devices are vulnerable if one or more of the following are enabled:
- IKEv2 Remote Access VPN (with client services)
- SSL-VPN (webvpn)
- Zero Trust Network Access (ZTNA)
## Vulnerability Description
The flaw exists due to insufficient error checking when the software processes crafted HTTP requests sent to the Remote Access SSL VPN service. An unauthenticated, remote attacker can exploit this by sending a specifically crafted HTTP request to the device, causing the system to reload unexpectedly.
## Exploitation
- **Status:** Exploited in the wild (Added to CISA KEV Catalog)
- **Complexity:** Low (Inferred based on CVSS and remote trigger)
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** None
- **Integrity:** None
- **Availability:** High (Triggers a device reload/Denial-of-Service condition)
## Remediation
### Patches
Cisco has released the following fixed versions/hotfixes:
- **ASA:** 89.16.4.50, 89.18.4.50, 9.20.4.235, 9.22.3.191, 9.23.1.211, 9.24.1.221
- **FTD:** Requires specific Hotfixes based on platform (e.g., SSP, FP1K, FP2K, FP3K) for versions 7.0 through 10.0. Refer to the Cisco advisory for the exact Hotfix filename for your hardware model.
### Workarounds
- There are **no workarounds** available that address this vulnerability. Administrators must apply the software updates or hotfixes.
## Detection
- **Indicators of Compromise:** Unexpected device reloads or crashes following unusual HTTP traffic to VPN endpoints.
- **Detection methods:** Monitor system logs for reload events and review incoming traffic to the SSL VPN service for anomalous HTTP patterns.
## References
- **Vendor Advisory:** hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF
- **CISA KEV Catalog:** hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog
- **News Source:** hxxps[://]thehackernews[.]com/2026/08/cisco-asa-and-ftd-flaw-exploited-in[.]html