CISA_KEV · AUGUST 2026 · CONFIRMED

CVE-2026-20349: Cisco ASA and FTD Vulnerability Exploited

Severity
HIGH
Affected component
cisco (other)
Patched version
Not yet available
CVE-2026-20349

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) have a high-severity vulnerability, tracked as CVE-2026-20349, that is being actively exploited to cause denial-of-service (DoS) conditions.

What happened

Cisco has confirmed that a vulnerability in their Secure Firewall ASA and FTD software, identified as CVE-2026-20349, is being exploited in the wild. This flaw allows an unauthenticated, remote attacker to send a specially crafted HTTP request to the Remote Access SSL VPN service, causing the affected device to reload and resulting in a DoS condition. The vulnerability arises from insufficient error checking during HTTP request processing.

The affected components include Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software with specific configurations enabled, such as IKEv2 Remote Access VPN, SSL-VPN, and Zero Trust Network Access. Although Cisco has provided fixed versions for various affected ASA and FTD versions, no authoritative version range has been published yet.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If cisco is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Cisco Secure Firewall ASA Software or Cisco Secure Firewall Threat Defense (FTD) Software with vulnerable configurations, you may be affected. Consult the primary sources for specific version details.

What should I do right now?

Monitor your devices for signs of exploitation and apply patches as they become available from Cisco. Review and update your configurations to mitigate risk.

Has this been exploited in the wild?

Yes, this vulnerability has been confirmed to be exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats