started · updated
Cisco warns of critical zero-day vulnerability in Secure Firewall ASA and FTD
Cisco has disclosed a critical zero-day vulnerability, CVE-2026-20349, affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. The flaw, which carries a CVSS score of 8.6, allows unauthenticated remote attackers to trigger a complete system crash by sending specially crafted HTTP requests to the Remote Access SSL VPN service. This results in a Denial of Service (DoS) state, causing immediate loss of VPN connectivity and disruption of firewall-mediated network traffic.
Active exploitation of this vulnerability has been confirmed. In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to remediate the issue. Cisco has released security patches to address the vulnerability, and organizations are urged to apply these updates immediately to prevent perimeter security failures and restore operational availability.
Entities
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 3 SOURCES] Unauthenticated remote attackers can trigger a complete system crash via malformed HTTP requests. flagthis.com · socprime.com · www.security-insider.de
- [● 3 SOURCES] The vulnerability has a CVSS score of 8.6. flagthis.com · socprime.com · www.security-insider.de
- [● 4 SOURCES] CVE-2026-20349 is a critical zero-day vulnerability affecting Cisco Secure Firewall ASA and FTD software. flagthis.com · socprime.com · www.security-insider.de · dev.to
- [● 2 SOURCES] CISA added the flaw to its Known Exploited Vulnerabilities catalog. socprime.com · www.security-insider.de