Cisco has patched a high severity denial of service vulnerability in its Secure Firewall ASA and FTD software that its own Product Security Incident Response Team confirmed is already under active exploitation. CISA has added the flaw to its Known Exploited Vulnerabilities catalog with a remediation deadline of August 14, 2026 for federal agencies, roughly a day out from this advisory’s publication.

The bug, CVE-2026-20349, carries a CVSS score of 8.6. Cisco’s advisory describes it as insufficient error checking in how the Remote Access SSL VPN service processes HTTP requests: an unauthenticated attacker can send a specially crafted request that forces the device to reload unexpectedly. It affects ASA and FTD deployments running IKEv2 Remote Access VPN with client services, SSL VPN on any interface, or Zero Trust Network Access on FTD, which describes most firewalls actually doing remote access duty. Cisco says there are no workarounds and no indicators of compromise defenders can currently check for, which leaves patching as the only real mitigation.

The original insight here is less about this one bug and more about Cisco’s perimeter products as a repeat target: this is the second Cisco firewall or firewall management flaw to reach CISA’s exploited list in as many weeks, following a hardcoded credential in Cisco’s Firewall Management Center. Attackers are not waiting for novel research; they are working through the same vendor’s edge devices as each new advisory lands, a pattern that also shows up in TP-Link’s recent Omada provisioning flaws. For any security team running Cisco ASA or FTD in a remote access configuration, this is not a routine patch cycle. Hotfixes are available now for every listed version, and the one day gap to CISA’s federal deadline is a reasonable proxy for how quickly this should move up the queue.

Source: Cisco