Cisco Warns of Active Exploitation in High-Severity Secure Firewall DoS Flaw
Cisco has issued a critical warning regarding a high-severity denial-of-service (DoS) vulnerability in its **Secure Firewall ASA** and **Threat Defense (FTD)** software. Tracked as **CVE-2026-20349**, this flaw is actively being exploited to remotely crash affected devices, posing a significant risk to network availability. Organizations are urged to apply hotfixes immediately as no workarounds exist.
## Critical DoS Vulnerability Under Active Attack
**Cisco** has confirmed that a serious denial-of-service (DoS) vulnerability, identified as **CVE-2026-20349**, is currently being exploited in the wild. This flaw, with a severity score of 8.6, impacts devices running **Cisco Secure Firewall Adaptive Security Appliance (ASA)** or **Secure Firewall Threat Defense (FTD)** software, specifically when certain remote access services are enabled.
The vulnerability stems from insufficient error checking during the processing of HTTP requests. An attacker can exploit this by sending a specially crafted HTTP request to the Remote Access SSL VPN service on a vulnerable device, leading to a device reload and a subsequent DoS condition.
### Exploitation Details and Impact
Exploitation of **CVE-2026-20349** is possible remotely, without the need for authentication or user interaction, provided that SSL listen sockets are enabled. Configurations susceptible to this attack include IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on **FTD** devices. Importantly, **Cisco Secure Firewall Management Center (FMC)** software is not affected by this particular vulnerability.
**Cisco's PSIRT** became aware of active exploitation in August 2026. While the company has not disclosed specific details about the attackers or targeted organizations, the immediate threat necessitates swift action from affected users.
### Remediation and Recommendations
**Cisco** has released hotfixes to address this critical issue. Patches are available for **ASA** releases 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, as well as **FTD** releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0.
Given the active exploitation and the absence of any viable workarounds, **Cisco** strongly advises all customers to upgrade to a fixed software release as soon as possible to fully remediate the vulnerability and protect their networks from potential disruption.
### Independent Discovery and Related Advisories
This vulnerability was discovered through **Cisco's** internal security testing and independently reported by security researcher **Valerio Brussani**.
In related news, **Cisco** also recently disclosed that its **Secure Endpoint Connector** for Windows, Mac, and Linux is vulnerable to **ClamAV** vulnerabilities with public exploits. Patches for these issues are expected to be released later this month.