Search
Find merged stories by title or summary.
CVE-2026-20349: Someone Is Crashing Cisco Firewalls. We Need to Talk About Why
An unauthenticated attacker can crash any Cisco ASA or FTD with SSL VPN exposed; it’s been confirmed exploited in the wild, and Cisco hasn’t told us who or why. Attackers Can Force Your Firewall To Reboot If you run a Cisco Adaptive Security Appliance or a Firepower Threat Defense device with Remote Access SSL VPN enabled, you are exposed to CVE-2026-20349. On August 11, 2026, Cisco published an advisory, scoring the vulnerability as “high” with a CVSS 3. 1 score of 8. 6. The flaw affects the Remote Access SSL VPN service on most ASA and FTD devices. Cisco describes the vulnerability as “insufficient error checking when processing HTTP requests,” which allows an unauthenticated remote attacker to send a crafted HTTP request and trigger an unexpected device reboot. The entire attack can be executed in one packet and requires no credentials or user interaction.
U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-20349 (CVSS score of 8.6) Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability • CVE-2026-68820 (CVSS score of 7.0) Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability • CVE-2026-72898 (CVSS score of 10.0) Metabase SQL Injection Vulnerability CVE-2026-20349 is a vulnerability in Cisco Secure Firewall ASA and FTD software that could allow unauthenticated, remote attackers to crash affected devices and cause a denial-of-service condition.
Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by August 14, 2026. Details about the attacks are currently under wraps. Cisco only shared that its Product Security Incident Response Team (PSIRT) became aware of active exploitation of this vulnerability in August … More → The post Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) appeared first on Help Net Security .
Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition
Security teams managing Cisco edge infrastructure face a high-priority patching deadline after Cisco confirmed active exploitation of a newly disclosed zero-day in its firewall VPN stack. Tracked as CVE-2026-20349, the flaw affects the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software and can force an unexpected device reload, creating a denial-of-service condition for remote access and related network paths. According to Cisco’s security advisory, the vulnerability stems from insufficient error checking when the SSL VPN service processes HTTP requests. An unauthenticated remote attacker can exploit the issue by sending a crafted HTTP request to the Remote Access SSL VPN service on an exposed device. No valid credentials are required.
Cisco security advisory (AV26-807)
Serial number: AV26-807 Date: August 12, 2026 As of August 11, 2026, Cisco is affected by a vulnerability in the following products: • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software • multiple versions • Cisco Secure Firewall Threat Defense (FTD) Software • multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. On August 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20349 to their Known Exploited Vulnerabilities (KEV) Database. • Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability • Cisco Security Advisories • CISA KEV: CVE-2026-20349 Cisco security advisory (AV26-807) - Canadian Centre for Cyber Security
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger
CVE-2026-20349 Detail - National Institute of Standards and Technology (.gov)
CVE-2026-20349 Detail National Institute of Standards and Technology (.gov)
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability • CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability • CVE-2026-72898 Metabase SQL Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
CVE-2026-20349 - Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
You've reached the end of current stories for this search.
