CVE Tools

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

SecurityWeekBy Eduard Kovacs

Reported exploitedSecure Firewall Adaptive Security ApplianceSecure Firewall Threat Defense

Our summary

Cisco has released emergency patches for a zero-day denial-of-service vulnerability affecting Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). The flaw, identified as CVE-2026-20349, permits remote attackers without authentication to trigger an appliance reload by sending malformed HTTP requests to the Remote Access SSL VPN service. With CISA adding the issue to its Known Exploited Vulnerabilities catalog due to confirmed active attacks since August 2026, organizations are urged to install the available hotfixes immediately to prevent network disruptions.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store