Cisco has warned of a high-severity denial-of-service (DoS) vulnerability in its Secure Firewall ASA and Threat Defense (FTD) software. Hackers are actively exploiting this flaw to remotely crash affected network devices.

Key Takeaways

  • Vulnerability CVE-2026-20349 carries a high severity score of 8.6.
  • Attackers can remotely crash devices without authentication or user interaction.
  • Affected services include SSL VPN, IKEv2, and Zero Trust Network Access.
  • Cisco has released urgent hotfixes for multiple software releases.

Cybersecurity giant Cisco has issued a critical advisory regarding a high-severity vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software. The flaw, identified as CVE-2026-20349, is currently being actively exploited in the wild to cause remote denial-of-service (DoS) conditions.

The vulnerability stems from insufficient error checking during the processing of HTTP requests. By sending a specially crafted HTTP request to the Remote Access SSL VPN service, an attacker can trigger an unexpected device reload. This effectively crashes the device, disrupting critical network connectivity and services.

Why This Matters

BozokMedia analysis shows that the most alarming aspect of this exploit is its ease of use; it requires no authentication or user interaction if SSL listen sockets are enabled. This makes it a potent tool for attackers looking to disrupt large-scale enterprise operations or create distractions for secondary attacks.

The ability to crash enterprise-grade hardware remotely without credentials makes this a top-tier threat to network stability.

The vulnerability impacts various configurations, including IKEv2 Remote Access VPN with client services and Zero Trust Network Access (ZTNA) on FTD devices. Fortunately, the Secure Firewall Management Center (FMC) software remains unaffected by this specific exploit.

Historical Background

Historically, VPN concentrators and edge security appliances have become primary targets for state-sponsored actors and cybercriminals. As organizations move toward remote-first work models, the perimeter security provided by tools like Cisco ASA has become the frontline of digital warfare, making these vulnerabilities highly sought after.

Frequently Asked Questions

1. Is there a workaround to prevent this attack?
No, Cisco has stated there are no workarounds available. The only way to remediate the vulnerability is to upgrade to a fixed software release.

2. Which software versions are safe?
Cisco has released specific hotfixes for ASA versions 9.16 through 9.24 and FTD releases 7.0 through 10.0. Check your specific version against the official advisory.

Did You Know?: A Denial-of-Service (DoS) attack doesn't necessarily steal data; its primary goal is to make a service unavailable to its intended users.