Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Cisco Flaw Exploited, Causes Remote DoS Risks

Critical Cisco Flaw Exploited, Causes Remote DoS Risks

Posted on August 12, 2026 By CWS

Cisco has raised alarms over a newly identified vulnerability affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. This security flaw, which has already been exploited in real-world attacks, poses a significant threat to network integrity.

Vulnerability Details and Impact

The vulnerability, designated as CVE-2026-20349 with a CVSS score of 8.6, arises from inadequate error handling during HTTP request processing. An unauthenticated attacker can exploit this flaw by sending specially crafted HTTP requests to the Remote Access SSL VPN service on vulnerable devices, potentially causing a denial-of-service (DoS) condition.

Cisco’s advisory highlights that successful exploitation could lead to the affected device reloading, resulting in service disruption. Devices running vulnerable versions of ASA or FTD software with specific configurations are particularly at risk.

Affected Versions and Patches

A wide range of ASA and FTD software versions are impacted, including ASA 9.161 through 9.24 and FTD versions 7.0 through 10.0. Cisco has released patches to address these vulnerabilities, with fixes available for each affected version.

For ASA, updates are provided starting from version 9.16.4.50. For FTD, hotfixes are available across versions 7.0 to 10.0, requiring administrators to implement these updates promptly to mitigate risks.

Agency and Industry Response

The vulnerability was uncovered during Cisco’s internal security assessments, and the company has acknowledged contributions from security researcher Valerio Brussani. As no workarounds exist for this issue, patching remains the sole mitigation strategy.

In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities catalog, urging Federal Civilian Executive Branch agencies to implement the necessary patches by August 14, 2026. This move underscores the critical nature of the threat and the importance of swift action.

While details on the specific attacks exploiting this vulnerability are scant, the proactive response from security agencies and Cisco itself highlights the need for vigilance in protecting network infrastructures against emerging threats.

The Hacker News Tags:ASA, CISA, Cisco, CVE-2026-20349, DoS, Exploitation, FTD, network security, Patches, Vulnerability

Post navigation

Previous Post: ShieldBreak: Critical Windows Defender Vulnerability Exposed
Next Post: Salesforce and ServiceNow Hit by ‘City-Forum’ Cyber Attacks

Related Posts

Why More Security Leaders Are Selecting AEV Why More Security Leaders Are Selecting AEV The Hacker News
SilkParasite Cyberattack Targets Central Asian Governments SilkParasite Cyberattack Targets Central Asian Governments The Hacker News
Cyber Criminals Exploit Open-Source Tools to Compromise Financial Institutions Across Africa Cyber Criminals Exploit Open-Source Tools to Compromise Financial Institutions Across Africa The Hacker News
DORA’s Impact on SOC Visibility: Key Insights DORA’s Impact on SOC Visibility: Key Insights The Hacker News
OpenSSL Vulnerabilities and Emerging Cyber Threats OpenSSL Vulnerabilities and Emerging Cyber Threats The Hacker News
Russian Cyber Campaign Targets Ukraine with New Malware Russian Cyber Campaign Targets Ukraine with New Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark