Cisco says attackers are actively crashing some of its firewall and VPN devices over the internet. The flaw, CVE-2026-20349, affects Cisco Secure Firewall ASA and Secure Firewall Threat Defense (FTD) when certain remote-access services are enabled, including SSL VPN, IKEv2 Remote Access VPN with client services, and Zero Trust Network Access on FTD. A crafted HTTP request to the Remote Access SSL VPN service can force the device to reload, causing a denial of service, and Cisco has released hotfixes for affected ASA 9.16/9.18/9.20/9.22/9.23/9.24 and FTD 7.0/7.2/7.4/7.6/7.7/10.0 releases.
Why it matters: Organizations using affected Cisco remote-access firewalls and VPN services could have internet-facing devices knocked offline, disrupting employee or customer access. This is urgent because exploitation is already happening and Cisco says there are no workarounds, so affected admins should apply the fixed releases or hotfixes immediately.
info@thehackernews.com (The Hacker News)
2026.08.12
99% relevant
The article appears to report the same underlying event: active exploitation of CVE-2026-20349 against Cisco ASA and Firepower Threat Defense devices, causing remote denial of service and reinforcing the need to apply Cisco’s fixes or mitigations.
Eduard Kovacs
2026.08.12
98% relevant
This source adds that Cisco has now released hotfixes for the actively exploited zero-day, confirms the issue is triggered by crafted HTTP requests to the Remote Access SSL VPN service, and notes CISA added CVE-2026-20349 to KEV with an August 14 patch deadline for federal agencies.
Lawrence Abrams
2026.08.11
100% relevant
This article establishes a distinct new exploitation and patching event for CVE-2026-20349 in Cisco Secure Firewall ASA and FTD; it is not the same underlying event as prior tracked Cisco FMC, Unified CM, SD-WAN, ISE, or ClamAV-related stories.
← Back to all stories