Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Reported exploitedSecure Firewall Adaptive Security ApplianceSecure Firewall Threat DefenseOur summary
Cisco has disclosed that attackers are actively exploiting a high-severity vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. Tracked as CVE-2026-20349, this flaw involves insufficient error handling during HTTP request processing, allowing unauthenticated remote attackers to force a device reload and cause a denial of service.
The advisory notes that exploitation targets specific configurations such as IKEv2, SSL-VPN, or Zero Trust Network Access. Organizations using affected versions should immediately apply the relevant hotfixes or upgrade to fixed releases, as CISA has added the issue to its Known Exploited Vulnerabilities catalog with a remediation deadline of August 14, 2026.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.