Cisco fixes ASA/FTD zero-day causing SSL VPN DoS
Cisco released hotfixes for CVE-2026-20349 in Secure Firewall ASA and FTD after unauthenticated actors used crafted HTTP requests to trigger appliance reloads and DoS.
Cisco released hotfixes on Tuesday for CVE-2026-20349, a vulnerability affecting Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software that allows remote, unauthenticated users to force appliances to reload and enter a denial-of-service state.
The flaw is tied to how the devices process HTTP requests sent to the Remote Access SSL VPN component. A specially crafted HTTP request can cause an appliance to restart, interrupting VPN access and disabling the firewall’s ability to inspect and block traffic while it is offline. Cisco identified the issue internally and received a separate report from an external researcher.
Cisco became aware of active exploitation of the vulnerability in August 2026 and has not released details about the attacks. Customers were advised to apply the vendor-provided hotfixes promptly to restore normal firewall and VPN operation.
The Cybersecurity and Infrastructure Security Agency added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog on Tuesday and instructed federal agencies to apply patches by August 14. The KEV listing indicates CISA has observed exploitation that meets its threshold for immediate remediation in federal networks. This is the 12th Cisco product vulnerability with a 2026 CVE identifier added to the KEV list this year.
Network operators should prioritize patching ASA and FTD appliances that offer Remote Access SSL VPN functionality. Where immediate patching is not possible, administrators can consider blocking or limiting access to the VPN service from untrusted networks and monitoring devices for unexpected reloads or service interruptions that could indicate exploitation attempts.
Appliances taken offline by a reload can prevent legitimate users from connecting and can reduce visibility into subsequent network traffic, which may affect an organization’s ability to detect further malicious activity.
Cisco’s advisory contains technical details and links to the hotfix downloads. Organizations with exposed instances are being asked to prioritize remediation and confirm successful installation of updates to restore firewall and VPN services.








