Cisco Patches Actively Exploited ASA, FTD VPN DoS Flaw CVE-2026-20349
CVE-2026-20349 (CVSS 8.6) lets unauthenticated remote attackers crash Cisco ASA and FTD VPN devices via crafted HTTP requests. Active exploitation confirmed; hotfixes available.

Executive Summary
Cisco is warning that a high-severity denial-of-service (DoS) vulnerability in its Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in the wild to remotely crash affected devices. Tracked as CVE-2026-20349 with a CVSS score of 8.6, the flaw stems from insufficient error checking while processing HTTP requests and can be triggered by an unauthenticated attacker sending a crafted request to the Remote Access SSL VPN service. Cisco has released hotfixes for all affected ASA and FTD releases but warns there are no workarounds — making immediate patching the only viable mitigation.
Technical Analysis
CVE-2026-20349 affects devices running Cisco Secure Firewall ASA or FTD software with certain remote access services enabled. The vulnerability originates from improper error handling when the device processes HTTP requests. An attacker can exploit this by sending a specially crafted HTTP request to the Remote Access SSL VPN service, causing the device to reload and resulting in a denial-of-service condition.
The flaw is remotely exploitable without authentication or user interaction when SSL listen sockets are enabled. Vulnerable configurations include:
- IKEv2 Remote Access VPN with client services
- SSL VPN
- Zero Trust Network Access on FTD devices
Cisco notes that Secure Firewall Management Center (FMC) software is not affected.
Cisco's PSIRT confirmed it became aware of active exploitation of CVE-2026-20349 in August 2026, but has not disclosed who is exploiting the vulnerability or which organizations are being targeted. The company also stated that the flaw was discovered during internal security testing and independently reported by security researcher Valerio Brussani. Cisco's advisory does not include indicators of compromise (IOCs) associated with the ongoing attacks.
Indicators of Compromise
Cisco has not published any IOCs for CVE-2026-20349. Defenders should monitor device logs for unusual HTTP requests targeting Remote Access SSL VPN endpoints, unexpected device reloads, or repeated crash events that may indicate exploitation attempts.
Tactics, Techniques & Procedures
The exploitation of CVE-2026-20349 aligns with the MITRE ATT&CK technique T1499 (Endpoint Denial of Service) under the Impact tactic. The attack vector — sending crafted HTTP requests to a public-facing VPN service — corresponds to T1190 (Exploit Public-Facing Application) under Initial Access. The lack of authentication and user interaction requirements makes this a low-complexity attack for adversaries seeking to disrupt network perimeter devices.
Threat Actor Context
Cisco has not attributed the active exploitation of CVE-2026-20349 to any specific threat actor or group. The company has not shared details about the attacks, including victimology or campaign infrastructure. As of now, the exploitation appears opportunistic, targeting internet-exposed VPN gateways.
Mitigations & Recommendations
Cisco has released hotfixes for affected ASA releases 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, as well as FTD releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. There are no workarounds for this vulnerability, so upgrading to a fixed software release is the only way to fully remediate the issue.
Defenders should:
- Apply the relevant hotfix immediately to all affected ASA and FTD devices, prioritizing internet-facing VPN gateways.
- Review device logs for unusual HTTP requests to Remote Access SSL VPN services, especially those preceding device reloads.
- Monitor Cisco's security advisories for updates, as the company has not yet provided IOCs or additional details about the exploitation.
- If patching is not immediately possible, consider restricting access to the Remote Access SSL VPN service from untrusted networks as a temporary measure, though this does not fully mitigate the risk.
Cisco also disclosed this month that Secure Endpoint Connector for Windows, Mac, and Linux is vulnerable to ClamAV flaws with public exploits, but patches are not yet available and will be released later this month. Organizations should track both issues and prioritize remediation based on their exposure.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.
