Cisco has patched CVE-2026-20349, a zero-day in Secure Firewall ASA and FTD software that can let a remote unauthenticated attacker trigger a reload and denial of service through a crafted HTTP request to the Remote Access SSL VPN service. Cisco said the flaw was actively exploited in August 2026, and CISA added it to the KEV catalog, urging federal agencies to patch by August 14. #Cisco #CVE-2026-20349 #SecureFirewallASA #SecureFirewallFTD #CISA #KnownExploitedVulnerabilities
Keypoints
- Cisco released hotfixes for CVE-2026-20349 in Secure Firewall ASA and FTD.
- The flaw affects HTTP request processing in the Remote Access SSL VPN service.
- A remote unauthenticated attacker can cause a reload and denial of service.
- Cisco confirmed active exploitation in August 2026.
- CISA added the bug to the KEV catalog and ordered federal patching by August 14.
Read More: https://www.securityweek.com/cisco-patches-firewall-zero-day-exploited-for-dos-attacks/