Cisco Warns of Actively Exploited DoS Vulnerability in Firewalls
**Cisco** has issued an urgent warning regarding a high-severity denial-of-service (DoS) vulnerability, **CVE-2026-20349**, actively exploited in the wild. The flaw impacts **Secure Firewall Adaptive Security Appliance (ASA) Software** and **Secure Firewall Threat Defense (FTD) Software**, potentially allowing unauthenticated attackers to trigger device reloads. IT security professionals are urged to apply patches immediately.
Network equipment giant **Cisco** has alerted users to a critical vulnerability, **CVE-2026-20349**, affecting its **Secure Firewall Adaptive Security Appliance (ASA) Software** and **Secure Firewall Threat Defense (FTD) Software**. This high-severity flaw, with a CVSS score of 8.6, is already being exploited in the wild.

### The Vulnerability Explained
The flaw stems from insufficient error checking when processing HTTP requests. An unauthenticated, remote attacker can exploit this by sending a specially crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit leads to a denial-of-service (DoS) condition, causing the device to reload.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device," **Cisco** stated in a recent advisory. "A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition."
### Affected Configurations and Versions
The security defect impacts devices running vulnerable versions of **Secure Firewall ASA Software** or **Cisco Secure FTD Software** with one or more of the following configurations enabled:
* **IKEv2 Remote Access VPN** (with client services): `crypto ikev2 enable <interface_name> client-services port <port_numbers>`
* **SSL-VPN**: `webvpn enable <interface_name>`
* **Zero Trust Network Access2**: `zero-trust enable`
The following versions of **ASA** and **FTD** are affected, with corresponding fixed versions:
* **ASA 9.16**: Fixed in 9.16.4.50
* **ASA 9.18**: Fixed in 9.18.4.50
* **ASA 9.20**: Fixed in 9.20.4.235
* **ASA 9.22**: Fixed in 9.22.3.191
* **ASA 9.23**: Fixed in 9.23.1.211
* **ASA 9.24**: Fixed in 9.24.1.221
* **FTD 7.0**: Fixed in various `Cisco_FTD_Hotfix_GC-7.0.9.1-1.sh.REL.tar` packages
* **FTD 7.2**: Fixed in various `Cisco_FTD_Hotfix_HM-7.2.11.1-2.sh.REL.tar` packages
* **FTD 7.4**: Fixed in various `Cisco_FTD_Hotfix_HK-7.4.7.1-1.sh.REL.tar` packages
* **FTD 7.6**: Fixed in various `Cisco_FTD_Hotfix_DD-7.6.4.1-2.sh.REL.tar` packages
* **FTD 7.7**: Fixed in various `Cisco_FTD_Hotfix_AN-7.7.11.1-2.sh.REL.tar` packages
* **FTD 10.0**: Fixed in various `Cisco_FTD_Hotfix_S-10.0.0.1-2.sh.REL.tar` packages
### No Workarounds, Immediate Patching Required
**Cisco** has confirmed that there are no workarounds to mitigate the flaw, emphasizing the urgency of applying the provided patches. The company became aware of active exploitation earlier this month, with the vulnerability initially discovered during internal security testing. **Valerio Brussani** is also credited for independently reporting the issue.
While details about the nature of the attacks, the threat actors involved, or the specific targets remain undisclosed, the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has already added **CVE-2026-20349** to its **Known Exploited Vulnerabilities (KEV) catalog**. Federal Civilian Executive Branch (FCEB) agencies are mandated to apply the fixes by August 14, 2026.