Cisco says CVE-2026-20349 is a high-severity flaw in Secure Firewall ASA and FTD software that is being actively exploited to remotely crash affected devices. The issue affects certain VPN and remote access configurations, has no workaround, and requires upgrading to a fixed release; Cisco has also released hot fixes for multiple ASA and FTD versions. #Cisco #CVE-2026-20349 #SecureFirewallASA #SecureFirewallFTD
Keypoints
- CVE-2026-20349 is an 8.6 severity denial-of-service flaw.
- The bug affects Cisco Secure Firewall ASA and FTD software.
- Attackers can exploit it with a crafted HTTP request to Remote Access SSL VPN services.
- A successful attack can force the device to reload and cause a DoS condition.
- Cisco has released hot fixes and recommends upgrading because no workaround exists.