Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Cisco Flaw Exploited, Causes Remote DoS Risks

Critical Cisco Flaw Exploited, Causes Remote DoS Risks

Posted on August 12, 2026 By CWS

Cisco has raised alarms over a newly identified vulnerability affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. This security flaw, which has already been exploited in real-world attacks, poses a significant threat to network integrity.

Vulnerability Details and Impact

The vulnerability, designated as CVE-2026-20349 with a CVSS score of 8.6, arises from inadequate error handling during HTTP request processing. An unauthenticated attacker can exploit this flaw by sending specially crafted HTTP requests to the Remote Access SSL VPN service on vulnerable devices, potentially causing a denial-of-service (DoS) condition.

Cisco’s advisory highlights that successful exploitation could lead to the affected device reloading, resulting in service disruption. Devices running vulnerable versions of ASA or FTD software with specific configurations are particularly at risk.

Affected Versions and Patches

A wide range of ASA and FTD software versions are impacted, including ASA 9.161 through 9.24 and FTD versions 7.0 through 10.0. Cisco has released patches to address these vulnerabilities, with fixes available for each affected version.

For ASA, updates are provided starting from version 9.16.4.50. For FTD, hotfixes are available across versions 7.0 to 10.0, requiring administrators to implement these updates promptly to mitigate risks.

Agency and Industry Response

The vulnerability was uncovered during Cisco’s internal security assessments, and the company has acknowledged contributions from security researcher Valerio Brussani. As no workarounds exist for this issue, patching remains the sole mitigation strategy.

In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities catalog, urging Federal Civilian Executive Branch agencies to implement the necessary patches by August 14, 2026. This move underscores the critical nature of the threat and the importance of swift action.

While details on the specific attacks exploiting this vulnerability are scant, the proactive response from security agencies and Cisco itself highlights the need for vigilance in protecting network infrastructures against emerging threats.

The Hacker News Tags:ASA, CISA, Cisco, CVE-2026-20349, DoS, Exploitation, FTD, network security, Patches, Vulnerability

Post navigation

Previous Post: ShieldBreak: Critical Windows Defender Vulnerability Exposed
Next Post: Salesforce and ServiceNow Hit by ‘City-Forum’ Cyber Attacks

Related Posts

Instructure Reaches Deal to Prevent Data Leak Instructure Reaches Deal to Prevent Data Leak The Hacker News
LastPass Warns of Fake Repositories Infecting macOS with Atomic Infostealer LastPass Warns of Fake Repositories Infecting macOS with Atomic Infostealer The Hacker News
Detour Dog Caught Running DNS-Powered Malware Factory for Strela Stealer Detour Dog Caught Running DNS-Powered Malware Factory for Strela Stealer The Hacker News
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers The Hacker News
Researchers Uncover Malware in Fake Discord PyPI Package Downloaded 11,500+ Times Researchers Uncover Malware in Fake Discord PyPI Package Downloaded 11,500+ Times The Hacker News
HalluSquatting Attack Threatens AI Coding Assistants HalluSquatting Attack Threatens AI Coding Assistants The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fake CCleaner Download Spreads GhostDesk Spyware
  • Mindgard Secures $30M to Enhance AI Security
  • Flaw in AI APIs Allows Extraction of Hidden Data
  • 2.86 Billion Stolen Credentials Impact Cybersecurity Landscape
  • Salesforce and ServiceNow Hit by ‘City-Forum’ Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fake CCleaner Download Spreads GhostDesk Spyware
  • Mindgard Secures $30M to Enhance AI Security
  • Flaw in AI APIs Allows Extraction of Hidden Data
  • 2.86 Billion Stolen Credentials Impact Cybersecurity Landscape
  • Salesforce and ServiceNow Hit by ‘City-Forum’ Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark