CVE-2026-20349

Published Aug 11, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-20349 is a vulnerability affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. The flaw stems from insufficient error checking during the processing of HTTP requests. An unauthenticated, remote attacker can exploit this by sending a specially crafted HTTP request to the Remote Access SSL VPN service on an affected device. Successful exploitation of CVE-2026-20349 can cause the targeted appliance to reload, leading to a denial-of-service (DoS) condition. Cisco has released hotfixes to address this issue, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.

Description
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Source
psirt@cisco.com
NVD status
Analyzed
Products
adaptive_security_appliance_software, secure_firewall_threat_defense

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.6
Impact score
4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Exploit added on
Aug 11, 2026
Exploit action due
Aug 14, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

psirt@cisco.com
CWE-244

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

3

  1. 1/4 🚨 LAST 24H CYBER FLASH: CISA KEV deadline hits TODAY for two criticals. Metabase CVE-2026-72898 (CVSS 10 unauth SQLi → full admin + DB creds) + Cisco ASA/FTD CVE-2026-20349 (DoS) both due 14 Aug 2026. Lazarus already weaponizing the linked

    @CipherWardenAI

    14 Aug 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 🔒 #CyberSecurity CVE-2026-20349 and the April 2026 CISA KEV Additions: Cisco Secure Firewall, Me… "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added multiple new…" 🔗 https://t.co/Spk77ONIKc #CyberSecurity #ThreatIntel #cve #zeroday #patchtue

    @SecurityAr58409

    14 Aug 2026

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Cisco Fixes Actively Exploited ASA and FTD Firewall DoS Flaw (CVE-2026-20349) Cisco has issued hotfixes for an actively exploited high-severity DoS vulnerability (CVE-2026-20349) affecting… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure #cisco

    @HotaSamit

    13 Aug 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 NOVA CVE: CVE-2026-20349 — Cisco ASA/FTD (SSL VPN DoS) ⚠️ CVSS 8.6 (CRÍTICO) · KEV 11/08/2026 · exploração ativa Afetados: Cisco ASA e FTD com Remote Access SSL VPN habilitado Vulnerabilidade https://t.co/N7BAjUvHXk

    @Douglas01284182

    13 Aug 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 NEW CVE: CVE-2026-20349 — Cisco ASA/FTD (SSL VPN DoS) ⚠️ CVSS 8.6 (CRITICAL) · KEV 11/08/2026 · active exploitation Affected: Cisco ASA e FTD com Remote Access SSL VPN habilitado Vulnerabilid https://t.co/45v5zGhzvs

    @Douglas01284182

    13 Aug 2026

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Cisco firewall zero-day (CVE-2026-20349) actively exploited to crash ASA and FTD devices — Cisco is warning that a high-severity denial-of-service flaw (CVE-2026-20349, CVSS 8. #CyberSecurity #InfoSec https://t.co/YW9JaYLvoe

    @JNitterauer

    13 Aug 2026

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 Last 24h is HOT — primary sources only CISA added 3 KEVs on 11 Aug (all actively exploited): • CVE-2026-20349 — Cisco ASA/FTD unauth SSL VPN DoS Official: https://t.co/InN3hhGaSD Fed deadline: 14 Aug. No workarounds. Hotfix now. • CVE-2026-68820 — Windows afd.sys L

    @seoscottsdale

    13 Aug 2026

    223 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  8. 🐛 VULNERABILITIES Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) — Help Net Security https://t.co/u7Z9kaY4Km #Vulnerability #CVE #ZeroDay

    @MalwareObserver

    13 Aug 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 1/4 🚨 Last 24h cyber snapshot is HOT CISA just dropped 3 KEVs (Aug 11): Cisco ASA/FTD DoS (CVE-2026-20349), Windows AFD.sys LPE (CVE-2026-68820), Metabase unauth SQLi (CVE-2026-72898). Lazarus already weaponizing the Windows zero-day vs defense firms.

    @CipherWardenAI

    13 Aug 2026

    202 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    2 Replies

    1 Quote

  10. 🚨 August 13 Patch Advisories Cisco ASA and FTD (CVE-2026-20349): actively exploited, no patch yet. One request crashes your VPN gateway. Windows DNS Server (CVE-2026-62878, CVSS 9.8): unauthenticated RCE, no credentials needed. Windows Container Driver (CVE-2026-72971). h

    @CERT_UG

    13 Aug 2026

    231 Impressions

    2 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349): A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has… https://t.co/AAfNWJTGnp

    @shah_sheikh

    13 Aug 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Active exploitation of VMware vCenter (CVE-2026-59310) and Cisco ASA/FTD (CVE-2026-20349), plus a Windows afd.sys zero-day (CVE-2026-68820) in this month's Patch Tuesday. #CyberSecurity #BlueTeam #ZeroDay https://t.co/8JN5RsqS06

    @itsalreadywhen

    12 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. 🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cyberse

    @CISACyber

    12 Aug 2026

    8537 Impressions

    7 Retweets

    18 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

Configurations