Denial of Service Vulnerability in Cisco Secure Firewall Products
CVE-2026-20349
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 11 August 2026
Badges
What is CVE-2026-20349?
CVE-2026-20349 is a vulnerability found in the Remote Access SSL VPN functionality of Cisco Secure Firewall products, specifically within the Adaptive Security Appliance (ASA) Software and Threat Defense (FTD) Software. This vulnerability arises from inadequate error checking during the processing of HTTP requests, allowing an unauthenticated remote attacker to exploit the flaw. By sending specially crafted HTTP requests to the affected VPN service, a successful exploitation could result in the unexpected reloading of the device, leading to a denial of service (DoS) condition. Given that Cisco Secure Firewalls are critical in safeguarding network environments, this vulnerability could severely impact operational continuity and expose systems to additional risks by disrupting essential security functions.
Potential impact of CVE-2026-20349
-
Denial of Service (DoS): The primary impact of this vulnerability is the potential for a denial of service that could render the affected firewall inoperable. This can disrupt network traffic and essential services, making it difficult for organizations to maintain normal operations.
-
Increased Attack Surface: By enabling unauthorized access through the exploitation of this vulnerability, attackers may gain insights into the network infrastructure, potentially leading to further attacks against connected systems or exploiting additional vulnerabilities within the network.
-
Operational Disruption: Continuous unavailability caused by repeated exploitation could not only lead to immediate downtime but also result in longer-term operational disruptions, impacting business productivity and possibly harming an organization’s reputation among clients and stakeholders.
CISA has reported CVE-2026-20349
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-20349 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1.28
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2
News Articles
Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day - Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight
4 weeks ago
Hackers are exploiting CVE 2026 20349 to crash Cisco firewalls
CVE-2026-20349 Cisco ASA/FTD is under active exploitation. Here is what makes exposed VPN gateways vulnerable and what IT teams should check now.
1 month ago
Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) - IT Security News
2026-08-13 10:08 A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw...
1 month ago
References
CVSS V3.1
Timeline
- 📈
Vulnerability started trending
- 📰
First article discovered by Securityweek
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved