Skip to main content
Emerging ThreatsMalware & Ransomware

Cisco Warns of Active Exploitation of VPN Flaw in ASA, FTD Software

Cisco security appliance on a rack surrounded by networking equipment indoors.

"An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device," Cisco explains in the advisory.

CVE-2026-20349: the technical failure and immediate effect

Cisco says CVE-2026-20349 is a high-severity denial-of-service vulnerability (CVSS 8.6) caused by insufficient error checking while processing HTTP requests. A successful exploit, Cisco warns, can force an affected Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) device to reload, producing a DoS condition that disrupts the appliance's operation.

The vendor specifies that the vulnerability can be triggered remotely without authentication or user interaction when SSL listen sockets are enabled, and that the attack vector is a "crafted HTTP request" sent to the Remote Access SSL VPN service on the affected device.

Affected Cisco Secure Firewall ASA and FTD configurations

  • The products and features Cisco names as vulnerable include ASA and FTD devices when certain remote access services are enabled: IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD devices.
  • Cisco also states Secure Firewall Management Center (FMC) software is not affected by this vulnerability.

Cisco's fixes, guidance, and what is not available

Cisco has released hot fixes for impacted releases. The fixed ASA releases are 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24. The fixed FTD releases are 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. In its advisory the company says there are no workarounds for the vulnerability and "strongly recommends that customers upgrade to a fixed software release to fully remediate the issue."

The advisory does not supply indicators of compromise (IOCs) associated with the active exploitation Cisco reports, leaving the published fixes as the only vendor-provided remediation path in the notice.

Active exploitation, discovery, and unanswered attribution

Cisco's Product Security Incident Response Team (PSIRT) says it became aware of active exploitation of CVE-2026-20349 in August 2026. Beyond confirming active exploitation, the company has not shared details about the attacks — including who is exploiting the flaw or what organizations are being targeted.

The vulnerability was found both during Cisco's internal security testing and via an independent report from researcher Valerio Brussani, Cisco says. The advisory likewise does not provide forensic indicators tied to the ongoing exploitation.

How technologists and procurement leaders are affected

  • Technologists and security teams: Cisco "strongly recommends" upgrading to fixed releases because no workarounds exist; the advisory's lack of IOCs and Cisco's limited disclosure on active exploitation will increase reliance on patching as the primary defense.
  • Procurement and affected enterprises: organizations that operate ASA or FTD appliances with the named remote access services enabled will need to coordinate timely installs of the specified hot fixes for ASA releases 9.16–9.24 and FTD releases 7.0–10.0 to fully remediate the issue.

Cisco also disclosed this month that Secure Endpoint Connector for Windows, Mac, and Linux is vulnerable to ClamAV vulnerabilities with public exploits; in that case Cisco says patches are not available yet but "will be released later this month." That second disclosure, paired with the ASA/FTD advisory, highlights concurrent remediation tasks in Cisco's product portfolio.

One empirical reminder from the company's broader reporting appears in the same source: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." The Blue Report 2026 cited there measures defenses technique by technique across 338 million simulations run in customer production environments — a data point the advisory includes as context.

Two facts stand out from Cisco's bulletin: a high-severity VPN-facing flaw (CVE-2026-20349) is being actively exploited, and the vendor's published fixes plus the recommendation to upgrade are the only complete mitigations the advisory lists, because no workarounds or IOCs are provided. For defenders, the immediate task is clear in Cisco's terms — apply the hot fixes for the listed ASA and FTD releases — even as questions about who is exploiting the vulnerability and which organizations are affected remain unanswered.

Original Cisco advisory summary at BleepingComputer