CVE-2026-20349: Cisco ASA and FTD Vulnerability Exploited
- Severity
- HIGH
- Affected component
- cisco (other)
- Patched version
- Not yet available
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) have a high-severity vulnerability, tracked as CVE-2026-20349, that is being actively exploited to cause denial-of-service (DoS) conditions.
What happened
Cisco has confirmed that a vulnerability in their Secure Firewall ASA and FTD software, identified as CVE-2026-20349, is being exploited in the wild. This flaw allows an unauthenticated, remote attacker to send a specially crafted HTTP request to the Remote Access SSL VPN service, causing the affected device to reload and resulting in a DoS condition. The vulnerability arises from insufficient error checking during HTTP request processing.
The affected components include Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software with specific configurations enabled, such as IKEv2 Remote Access VPN, SSL-VPN, and Zero Trust Network Access. Although Cisco has provided fixed versions for various affected ASA and FTD versions, no authoritative version range has been published yet.
What to do about it
- Monitor for any signs of exploitation on your devices.
- Apply patches as soon as they become available from Cisco.
- Review and update your device configurations to disable unnecessary services that may be vulnerable.
- No official fix has been published yet for all affected versions. Monitor the sources below for updates.
How 0Day would have caught this
cisco is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Cisco Secure Firewall ASA Software or Cisco Secure Firewall Threat Defense (FTD) Software with vulnerable configurations, you may be affected. Consult the primary sources for specific version details.
What should I do right now?
Monitor your devices for signs of exploitation and apply patches as they become available from Cisco. Review and update your configurations to mitigate risk.
Has this been exploited in the wild?
Yes, this vulnerability has been confirmed to be exploited in the wild.
Sources
- NCSC-2026-0295 [1.00] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall ASA en FTD software
- Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
- Cisco warns of ASA and FTD VPN flaw exploited to crash devices
- [CISA KEV] CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Cisco Patches Firewall Zero-Day Exploited for DoS Attacks