Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
Reported exploitedSecure Firewall Adaptive Security ApplianceSecure Firewall Threat DefenseOur summary
Cisco has released emergency patches for a zero-day denial-of-service vulnerability affecting Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). The flaw, identified as CVE-2026-20349, permits remote attackers without authentication to trigger an appliance reload by sending malformed HTTP requests to the Remote Access SSL VPN service. With CISA adding the issue to its Known Exploited Vulnerabilities catalog due to confirmed active attacks since August 2026, organizations are urged to install the available hotfixes immediately to prevent network disruptions.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.