---
schema: 1
kind: vulnerability
title: "CVE-2026-20349 — Cisco Secure Firewall ASA/FTD: one crafted HTTP request to the Remote Access SSL VPN reloads the device, exploitation confirmed, no workaround and a three-day KEV deadline"
headline: "Cisco confirms active exploitation of an unauthenticated ASA/FTD VPN denial-of-service flaw with hot fixes as the only control"
summary: >
  Cisco disclosed CVE-2026-20349 on 2026-08-11 and states its PSIRT became aware of active
  exploitation in August 2026. Insufficient error checking when the Remote Access SSL VPN service
  parses HTTP requests lets an unauthenticated remote attacker send one crafted request and force
  the device to reload. Any ASA or FTD device with SSL listen sockets enabled is affected — IKEv2
  remote access with client services, SSL VPN, or Zero Trust Network Access — across ASA 9.16 to
  9.24 and FTD 7.0 to 10.0; Secure Firewall Management Center is not affected. There are no
  workarounds, only hot fixes, and CISA added the CVE to its KEV catalog the same day with a
  14 August deadline.
discovered_at: "2026-08-12T04:46:00Z"
event_date: "2026-08-11"
run_id: 2026-08-12T0411Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, actively-exploited, pre-auth, dos, cisa-kev, patch-available]
regions: [global, europe]
sectors: [public-sector, energy, healthcare, finance, telco, transport]
entities: []
techniques: [T1190, T1499.004]
affected_products: ["Cisco Secure Firewall Adaptive Security Appliance (ASA)", "Cisco Secure Firewall Threat Defense (FTD)"]
cves:
  - id: CVE-2026-20349
    cvss: "8.6"
    epss: null
    type: dos
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "Cisco Secure Firewall ASA 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24; Cisco Secure FTD 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0, where SSL listen sockets are enabled"
    fixed: "Per-train hot fixes in the advisory — ASA 89.16.4.50, 89.18.4.50, 9.20.4.235, 9.22.3.191, 9.23.1.211, 9.24.1.221; FTD hot-fix packages per release"
sources:
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF"
    publisher: "Cisco PSIRT"
    date: "2026-08-11"
    role: primary
  - url: "https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog"
    publisher: "CISA"
    date: "2026-08-11"
    role: corroborating
closed_sources: []
evidence:
  - quote: "In August 2026, the Cisco Product Security Incident Response Team (PSIRT) became aware of active exploitation of this vulnerability."
    publisher: "Cisco PSIRT"
  - quote: "There are no workarounds that address this vulnerability."
    publisher: "Cisco PSIRT"
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Run `show running-config` against every internet-facing ASA/FTD and apply the per-train hot fix wherever `webvpn enable`, `crypto ikev2 enable ... client-services`, or `zero-trust enable` appears on an interface — those three configurations are what expose the SSL listen sockets, and no workaround exists."
migrated_from: null
---

Cisco published advisory `cisco-sa-asaftd-vpn-dos-dzv4mQFF` on 2026-08-11 at 16:39 GMT covering CVE-2026-20349, and states plainly that "In August 2026, the Cisco Product Security Incident Response Team (PSIRT) became aware of active exploitation of this vulnerability" ([Cisco PSIRT, 2026-08-11](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF)). The flaw is insufficient error checking when the Remote Access SSL VPN service on Secure Firewall ASA and Secure Firewall Threat Defense processes HTTP requests: an unauthenticated remote attacker sends a crafted HTTP request to that service and causes the device to reload, producing a denial of service. Cisco scores it CVSS 8.6 (`AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H`) under CWE-244, rates the advisory High, and states "There are no workarounds that address this vulnerability" ([Cisco PSIRT, 2026-08-11](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF)).

The exposure question is a configuration question, and Cisco makes it checkable rather than leaving it to guesswork. Three features enable the SSL listen sockets the attack reaches: IKEv2 remote-access VPN with client services (`crypto ikev2 enable <interface> client-services port <ports>`), SSL VPN (`webvpn enable <interface>`), and Zero Trust Network Access (`zero-trust enable`, FTD only) ([Cisco PSIRT, 2026-08-11](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF)). A device with none of them configured is not affected regardless of version. Affected releases are ASA 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24 and FTD 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0, with per-train hot fixes listed in the advisory; Cisco confirms Secure Firewall Management Center is not affected. One deployment footnote worth carrying into the change ticket: the ASA hot fixes for the 9.16 and 9.18 trains use a release-numbering format beginning `89`, and Cisco tells customers installing those to move to ASDM 7.24.1.374 because earlier ASDM releases do not recognise that format.

CISA added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog on 2026-08-11 with a 14 August due date, and catalogues it as a heap-inspection weakness ([CISA, 2026-08-11](https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog)). The US federal deadline is not this constituency's clock, but the listing itself is the jurisdiction-agnostic part: it is independent confirmation that the flaw is being used, on a class of device — the remote-access VPN gateway — where an outage is a availability incident for every remote worker at once.

Two things keep this at `high` rather than `critical`. Cisco scopes the impact to a device reload with no confidentiality or integrity effect in its own vector string, and names no exploiting cluster or targeted sector. What makes it worth acting on inside the week anyway is the combination the advisory itself documents: unauthenticated, single-request, no workaround, on a service whose whole purpose is to be reachable from the internet. Detection here is unusually blunt and unusually reliable — the exploitation signal *is* the impact. Repeated unexplained reloads or crash-dump generation on an internet-facing ASA/FTD, particularly clustered around inbound HTTP requests to the SSL VPN listener rather than around a configuration change or a scheduled reload, is the hunt; syslog reload events correlated against the VPN service's request logs will separate a exploitation attempt from an operator-initiated reboot, because the latter carries a corresponding administrative session and the former does not.
