Cisco published an advisory on Aug. 11 warning that a vulnerability in its firewall software allows an unauthenticated, remote attacker to force affected devices to reload unexpectedly, producing a denial-of-service condition. The Cybersecurity and Infrastructure Security Agency added the flaw, tracked as CVE-2026-20349, to its Known Exploited Vulnerabilities catalog the same day and set a federal civilian remediation deadline of Aug. 14.
he vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) software.
According to Cisco’s advisory, the flaw stems from the software’s failure to properly check for errors when processing HTTP requests. An attacker exploits it by sending malformed HTTP requests to the Remote Access SSL VPN service. The error handling does not catch the malformed input, and the device reloads.
No authentication is required, and no user interaction is involved. Because the affected service is a remote-access VPN endpoint, it is by design reachable from untrusted networks, which limits the effectiveness of source-address restrictions as a mitigation. Nothing in the flaw restricts an attacker to a single attempt.
The vulnerability is server-side. Cisco AnyConnect and Cisco Secure Client endpoints do not require updating.
Fixed versions across multiple ASA and FTD trains were released and customer upgrade is strongly recommended
KEV inclusion indicates confirmed exploitation in the wild rather than theoretical risk. The catalog entry and Cisco’s advisory were published the same day.
Network edge appliances accumulate this class of finding for structural reasons. They are internet-facing by design, terminate encrypted sessions, are patched on slower cycles because patching interrupts service, and typically fall outside endpoint detection and response coverage.

Leave a Reply