Denial of Service Vulnerability in Cisco Secure Firewall Products
CVE-2026-20349

8.6HIGH

Key Information:

Badges

🔥 Trending now📈 Trended📈 Score: 2,100👾 Exploit Exists🦅 CISA Reported

What is CVE-2026-20349?

CVE-2026-20349 is a vulnerability found in the Remote Access SSL VPN functionality of Cisco Secure Firewall products, specifically within the Adaptive Security Appliance (ASA) Software and Threat Defense (FTD) Software. This vulnerability arises from inadequate error checking during the processing of HTTP requests, allowing an unauthenticated remote attacker to exploit the flaw. By sending specially crafted HTTP requests to the affected VPN service, a successful exploitation could result in the unexpected reloading of the device, leading to a denial of service (DoS) condition. Given that Cisco Secure Firewalls are critical in safeguarding network environments, this vulnerability could severely impact operational continuity and expose systems to additional risks by disrupting essential security functions.

Potential impact of CVE-2026-20349

  1. Denial of Service (DoS): The primary impact of this vulnerability is the potential for a denial of service that could render the affected firewall inoperable. This can disrupt network traffic and essential services, making it difficult for organizations to maintain normal operations.

  2. Increased Attack Surface: By enabling unauthorized access through the exploitation of this vulnerability, attackers may gain insights into the network infrastructure, potentially leading to further attacks against connected systems or exploiting additional vulnerabilities within the network.

  3. Operational Disruption: Continuous unavailability caused by repeated exploitation could not only lead to immediate downtime but also result in longer-term operational disruptions, impacting business productivity and possibly harming an organization’s reputation among clients and stakeholders.

CISA has reported CVE-2026-20349

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-20349 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1.28

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 📈

    Vulnerability started trending

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.