Full Report
Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. [...]
Analysis Summary
# Vulnerability: Cisco ASA and FTD Remote Access SSL VPN Denial of Service
## CVE Details
- **CVE ID:** CVE-2026-20349
- **CVSS Score:** 8.6 (High)
- **CWE:** Insufficient error checking (CWE-20 Improper Input Validation)
## Affected Systems
- **Products:**
- Cisco Secure Firewall Adaptive Security Appliance (ASA)
- Cisco Secure Firewall Threat Defense (FTD)
- **Versions:**
- ASA: 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24
- FTD: 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0
- **Configurations:** Devices are vulnerable if SSL listen sockets are enabled for any of the following:
- IKEv2 Remote Access VPN with client services
- SSL VPN (AnyConnect)
- Zero Trust Network Access (ZTNA) on FTD devices
## Vulnerability Description
The flaw exists due to insufficient error checking by the software when processing incoming HTTP requests. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to the Remote Access SSL VPN service interface. This causes an internal process failure that forces the device to reload (reboot), resulting in a complete Denial of Service (DoS) for all traffic and VPN tunnels.
## Exploitation
- **Status:** Exploited in the wild (as of August 2026)
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** None
- **Integrity:** None
- **Availability:** High (Device reload/crash leads to sustained DoS during reboot cycles)
## Remediation
### Patches
Cisco has released hotfixes and software updates for the following affected release trains:
- **ASA:** 9.16, 9.18, 9.20, 9.22, 9.23, 9.24
- **FTD:** 7.0, 7.2, 7.4, 7.6, 7.7, 10.0
*Note: Users should consult the Cisco Software Central portal for the specific maintenance release or hotfix for their respective version.*
### Workarounds
- **None:** There are no available workarounds for this vulnerability. Upgrading to a fixed software release is the only remediation.
## Detection
- **Indicators of Compromise:** No specific Indicators of Compromise (IoCs) like malicious IPs or file hashes have been released by Cisco at this time.
- **Detection methods and tools:**
- Monitor for unexpected device reloads/reboots without a clear hardware cause.
- Review logs for unusual HTTP requests targeting the VPN gateway interface.
- Cisco Secure Firewall Management Center (FMC) is **not** affected but can be used to push updates to managed FTD devices.
## References
- **Vendor Advisory:** hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF
- **BleepingComputer Report:** hxxps[://]www[.]bleepingcomputer[.]com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/