CVE-2026-20349 (CVSS score: 8.6) is an actively exploited, high-severity vulnerability in Cisco Secure Firewall ASA and FTD software that can be triggered by a crafted HTTP request and cause affected devices to reload, producing a remote denial-of-service condition.
CVE-2026-20349: how Cisco describes the flaw
Cisco warned that the flaw is "a case of insufficient error checking when processing HTTP requests" and that "an attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device." The vendor added that "a successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition," in a Tuesday advisory.
Vulnerable configurations and how the exploit takes place
- The vulnerability affects devices running vulnerable versions of Secure Firewall Adaptive Security Appliance (ASA) Software or Secure Firewall Threat Defense (FTD) Software when one or more of these configurations is present:
- IKEv2 Remote Access VPN (with client services) — crypto ikev2 enable <interface_name> client-services port <port_numbers>
- SSL‑VPN — webvpn enable <interface_name>
- Zero Trust Network Access2 — zero-trust enable
- Exploitation requires sending a specially crafted HTTP request to the Remote Access SSL VPN service on the affected device; no authentication is required for an attacker to attempt the exploit, per the advisory.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleProduct versions and published fixes
- ASA versions affected (and the builds Cisco says fix the issue):
- ASA 9.161 — Fixed in 89.16.4.50
- ASA 9.181 — Fixed in 89.18.4.50
- ASA 9.20 — Fixed in 9.20.4.235
- ASA 9.22 — Fixed in 9.22.3.191
- ASA 9.23 — Fixed in 9.23.1.211
- ASA 9.24 — Fixed in 9.24.1.221
- FTD versions and hotfix packages Cisco lists as fixes:
- FTD 7.0 — patches:
- Cisco_FTD_Hotfix_GC-7.0.9.1-1.sh.REL.tar
- Cisco_FTD_SSP_FP1K_Hotfix_GC-7.0.9.1-1.sh.REL.tar
- Cisco_FTD_SSP_FP2K_Hotfix_GC-7.0.9.1-1.sh.REL.tar
- Cisco_FTD_SSP_Hotfix_GC-7.0.9.1-1.sh.REL.tar
- FTD 7.2 — patches:
- Cisco_FTD_Hotfix_HM-7.2.11.1-2.sh.REL.tar
- Cisco_FTD_SSP_FP1K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
- Cisco_FTD_SSP_FP2K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
- Cisco_FTD_SSP_FP3K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
- Cisco_FTD_SSP_Hotfix_HM-7.2.11.1-2.sh.REL.tar
- FTD 7.4 — patches:
- Cisco_FTD_Hotfix_HK-7.4.7.1-1.sh.REL.tar
- Cisco_FTD_SSP_FP1K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
- Cisco_FTD_SSP_FP2K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
- Cisco_FTD_SSP_FP3K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
- Cisco_FTD_SSP_Hotfix_HK-7.4.7.1-1.sh.REL.tar
- Cisco_Secure_FW_TD_4200_Hotfix_HK-7.4.7.1-1.sh.REL.tar
- FTD 7.6 — patches:
- Cisco_FTD_Hotfix_DD-7.6.4.1-2.sh.REL.tar
- Cisco_FTD_SSP_FP1K_Hotfix_DD-7.6.4.1-2.sh.REL.tar
- Cisco_FTD_SSP_FP3K_Hotfix_DD-7.6.4.1-2.sh.REL.tar
- Cisco_FTD_SSP_Hotfix_DD-7.6.4.1-2.sh.REL.tar
- Cisco_Secure_FW_TD_4200_Hotfix_DD-7.6.4.1-2.sh.REL.tar
- FTD 7.7 — patches:
- Cisco_FTD_Hotfix_AN-7.7.11.1-2.sh.REL.tar
- Cisco_FTD_SSP_FP1K_Hotfix_AN-7.7.11.1-2.sh.REL.tar
- Cisco_FTD_SSP_FP3K_Hotfix_AN-7.7.11.1-2.sh.REL.tar
- Cisco_FTD_SSP_Hotfix_AN-7.7.11.1-2.sh.REL.tar
- Cisco_Secure_FW_TD_1200_Hotfix_AN-7.7.11.1-2.sh.REL.tar
- Cisco_Secure_FW_TD_4200_Hotfix_AN-7.7.11.1-2.sh.REL.tar
- FTD 10.0 — patches:
- Cisco_FTD_Hotfix_S-10.0.0.1-2.sh.REL.tar
- Cisco_FTD_SSP_FP1K_Hotfix_S-10.0.0.1-2.sh.REL.tar
- Cisco_FTD_SSP_FP3K_Hotfix_S-10.0.0.1-2.sh.REL.tar
- Cisco_FTD_SSP_Hotfix_S-10.0.0.1-2.sh.REL.tar
- Cisco_Secure_FW_TD_200_Hotfix_R-10.0.0.1-2.sh.REL.tar
- Cisco_Secure_FW_TD_1200_Hotfix_S-10.0.0.1-2.sh.REL.tar
- Cisco_Secure_FW_TD_4200_Hotfix_S-10.0.0.1-2.sh.REL.tar
- Cisco_Secure_FW_TD_6100_Hotfix_S-10.0.0.1-2.sh.REL.tar
- FTD 7.0 — patches:
No workarounds, discovery and credited researcher
Cisco stated there are no workarounds that address CVE-2026-20349 and said it became aware of active exploitation earlier this month. The issue was found during Cisco's internal security testing, and the company credited Valerio Brussani for separately discovering and reporting the vulnerability.
CISA action and the federal patching deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20349 to its Known Exploited Vulnerabilities (KEV) catalog. Inclusion in the KEV catalog requires Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by August 14, 2026.
How technologists, FCEB agencies, and affected enterprises should respond
- Technologists and security teams: verify which ASA and FTD builds are in use, check for the listed vulnerable configurations (IKEv2 Remote Access VPN client-services, SSL‑VPN webvpn enable, and Zero Trust Network Access2 zero-trust enable), and plan to apply the specific fixes or hotfix packages that correspond to your platform and build.
- FCEB agencies and regulators: the KEV listing creates a binding deadline — agencies covered by the Federal Civilian Executive Branch must install the provided fixes by August 14, 2026.
- Affected enterprises and procurement leaders: prioritize inventorying firewall and VPN endpoints running the named ASA and FTD versions and schedule the hotfixes or upgrades listed by Cisco; Cisco has said no workaround exists, making timely deployment the main mitigation available from the vendor.
There are limits to the public record: Cisco's advisory and related reporting make clear the vulnerability is being exploited in the wild but do not provide details about the nature of the attacks, the identity or origins of the threat actor, which organizations — if any — have been targeted, or whether any exploitation attempts succeeded. The immediate, verifiable steps for defenders are explicit in Cisco's advisory and the CISA KEV listing: identify affected devices and apply the vendor-provided fixes before the federal deadline.




