Overview
- Cisco released hotfixes for multiple ASA and FTD releases after confirming active exploitation of CVE-2026-20349 that can cause affected firewalls to reload and enter a denial-of-service state.
- The bug stems from insufficient error checking of HTTP requests to the Remote Access SSL VPN service and can be triggered remotely without authentication when SSL listen sockets are enabled.
- Vulnerable configurations include IKEv2 remote access VPN with client services, SSL VPN, and Zero Trust Network Access on ASA and FTD devices, and Cisco says there are no workarounds.
- Cisco discovered the flaw during internal testing and credited researcher Valerio Brussani for an independent report, but the company has not published indicators of compromise or identified who is attacking or which organizations were hit.
- The U.S. Cybersecurity and Infrastructure Security Agency added the CVE to its Known Exploited Vulnerabilities list, set an accelerated federal patch deadline, and defenders face harder detection and recovery because public details about the attacks remain limited.