< Back to all clusters
[TECHNOLOGY] · United States · 9 sources

started · updated

Cisco warns of critical zero-day vulnerability in Secure Firewall ASA and FTD

Cisco has disclosed a critical zero-day vulnerability, CVE-2026-20349, affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. The flaw, which carries a CVSS score of 8.6, allows unauthenticated remote attackers to trigger a complete system crash by sending specially crafted HTTP requests to the Remote Access SSL VPN service. This results in a Denial of Service (DoS) state, causing immediate loss of VPN connectivity and disruption of firewall-mediated network traffic.

Active exploitation of this vulnerability has been confirmed. In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to remediate the issue. Cisco has released security patches to address the vulnerability, and organizations are urged to apply these updates immediately to prevent perimeter security failures and restore operational availability.

Entities

ASUS · CISA · Cisco · Fortinet

Claims

What the coverage asserts, and how well corroborated each claim is across sources.