Denial of Service Vulnerability in Cisco Secure Firewall Products
CVE-2026-20349
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 11 August 2026
Badges
What is CVE-2026-20349?
CVE-2026-20349 is a vulnerability found in the Remote Access SSL VPN functionality of Cisco Secure Firewall products, specifically within the Adaptive Security Appliance (ASA) Software and Threat Defense (FTD) Software. This vulnerability arises from inadequate error checking during the processing of HTTP requests, allowing an unauthenticated remote attacker to exploit the flaw. By sending specially crafted HTTP requests to the affected VPN service, a successful exploitation could result in the unexpected reloading of the device, leading to a denial of service (DoS) condition. Given that Cisco Secure Firewalls are critical in safeguarding network environments, this vulnerability could severely impact operational continuity and expose systems to additional risks by disrupting essential security functions.
Potential impact of CVE-2026-20349
-
Denial of Service (DoS): The primary impact of this vulnerability is the potential for a denial of service that could render the affected firewall inoperable. This can disrupt network traffic and essential services, making it difficult for organizations to maintain normal operations.
-
Increased Attack Surface: By enabling unauthorized access through the exploitation of this vulnerability, attackers may gain insights into the network infrastructure, potentially leading to further attacks against connected systems or exploiting additional vulnerabilities within the network.
-
Operational Disruption: Continuous unavailability caused by repeated exploitation could not only lead to immediate downtime but also result in longer-term operational disruptions, impacting business productivity and possibly harming an organization’s reputation among clients and stakeholders.
CISA has reported CVE-2026-20349
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-20349 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1.28
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2
References
CVSS V3.1
Timeline
- 📈
Vulnerability started trending
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved