CVE Tools

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

The Hacker NewsBy The Hacker News

Reported exploitedSecure Firewall Adaptive Security ApplianceSecure Firewall Threat Defense

Our summary

Cisco has disclosed that attackers are actively exploiting a high-severity vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. Tracked as CVE-2026-20349, this flaw involves insufficient error handling during HTTP request processing, allowing unauthenticated remote attackers to force a device reload and cause a denial of service.

The advisory notes that exploitation targets specific configurations such as IKEv2, SSL-VPN, or Zero Trust Network Access. Organizations using affected versions should immediately apply the relevant hotfixes or upgrade to fixed releases, as CISA has added the issue to its Known Exploited Vulnerabilities catalog with a remediation deadline of August 14, 2026.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store