Cisco has raised alarms over a newly identified vulnerability affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. This security flaw, which has already been exploited in real-world attacks, poses a significant threat to network integrity.
Vulnerability Details and Impact
The vulnerability, designated as CVE-2026-20349 with a CVSS score of 8.6, arises from inadequate error handling during HTTP request processing. An unauthenticated attacker can exploit this flaw by sending specially crafted HTTP requests to the Remote Access SSL VPN service on vulnerable devices, potentially causing a denial-of-service (DoS) condition.
Cisco’s advisory highlights that successful exploitation could lead to the affected device reloading, resulting in service disruption. Devices running vulnerable versions of ASA or FTD software with specific configurations are particularly at risk.
Affected Versions and Patches
A wide range of ASA and FTD software versions are impacted, including ASA 9.161 through 9.24 and FTD versions 7.0 through 10.0. Cisco has released patches to address these vulnerabilities, with fixes available for each affected version.
For ASA, updates are provided starting from version 9.16.4.50. For FTD, hotfixes are available across versions 7.0 to 10.0, requiring administrators to implement these updates promptly to mitigate risks.
Agency and Industry Response
The vulnerability was uncovered during Cisco’s internal security assessments, and the company has acknowledged contributions from security researcher Valerio Brussani. As no workarounds exist for this issue, patching remains the sole mitigation strategy.
In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities catalog, urging Federal Civilian Executive Branch agencies to implement the necessary patches by August 14, 2026. This move underscores the critical nature of the threat and the importance of swift action.
While details on the specific attacks exploiting this vulnerability are scant, the proactive response from security agencies and Cisco itself highlights the need for vigilance in protecting network infrastructures against emerging threats.
