Cisco warns of ASA and FTD VPN flaw exploited to crash devices
Reported exploitedCisco Secure Firewall ASACisco Secure Firewall Threat Defense (FTD)Our summary
Cisco has released hot fixes for CVE-2026-20349, a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software that is currently being actively exploited to crash devices. The flaw, which stems from insufficient error handling of HTTP requests, allows attackers to remotely trigger a device reload without authentication or user interaction when specific remote access services like SSL VPN are enabled. Affected products include ASA versions 9.16 through 9.24 and FTD releases 7.0 through 10.0, though Secure Firewall Management Center remains unaffected. Since there are no workarounds, administrators should immediately upgrade their systems to the patched releases provided by Cisco.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.