Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to Remote Access SSL VPN

Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) (TL-2026-1993) is a high-severity software vulnerability scored CVSS 8.6, first published 2026-08-12 and last reviewed 2026-08-15. It has no confirmed attribution, affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, references 1 CVE (CVE-2026-20349), maps to 16 MITRE ATT&CK techniques (T1190, T1499, T1499.004), and is covered by 9 detection rules and 31 indicators of compromise.

Key facts for TL-2026-1993

Threat ID
TL-2026-1993
Severity
HIGH
CVSS
8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-08-12
Last reviewed
2026-08-15
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
31
Updates
2026-08-15 · 2 updates · revalidated 2× · latest source

Cisco patched CVE-2026-20349, an unauthenticated, remotely exploitable denial-of-service flaw in the Remote Access SSL VPN service of Secure Firewall ASA and FTD software, after confirming active exploitation. CISA added the CVSS 8.6 flaw to its Known Exploited Vulnerabilities catalog on 2026-08-11 with a federal patch deadline of 2026-08-14; Cisco has released hotfixes for all affected releases but no workaround exists.

How Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) works

On 2026-08-11 Cisco published Security Advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF disclosing CVE-2026-20349, a denial-of-service vulnerability affecting Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. The root cause is insufficient error checking while processing HTTP requests to the Remote Access SSL VPN (webvpn) service: a remote, unauthenticated attacker can send a specially crafted HTTP request that forces the device to reload unexpectedly, producing a denial-of-service condition. The flaw is tracked under CWE-244 (Improper Clearing of Heap Memory Before Release / Heap Inspection) and carries a CVSS 3.1 base score of 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H) — network-exploitable, low complexity, no privileges or user interaction required, scope changed, availability impact high, no confidentiality/integrity impact. Cisco's advisory does not disclose the precise parsing/heap-handling defect that triggers the crash, nor the exact structure of the crafted request.

A device is vulnerable only when one of several remote-access features creates an SSL listening socket: IKEv2 Remote Access VPN with client services (`crypto ikev2 enable <interface> client-services port <port>`), SSL VPN/webvpn enabled on an interface (`webvpn` / `enable <interface>`), or Zero Trust Network Access on FTD (`zero-trust enable`). Cisco Secure Firewall Management Center (FMC) is not affected. The bug was found during Cisco's internal security testing and independently reported by external researcher Valerio Brussani.

Cisco's PSIRT confirmed it became aware of active in-the-wild exploitation of CVE-2026-20349 in August 2026 but has not disclosed the identity of the attacker(s), the scale of exploitation, or which organizations/sectors were targeted, and the advisory explicitly states it does not provide indicators of compromise associated with the ongoing exploitation. To help defenders detect exploitation attempts despite the absence of published attacker infrastructure IOCs, Cisco published two Snort detection rule signature IDs — SID 46897 and SID 59654 — for the vulnerable HTTP request pattern against the Remote Access SSL VPN service.

CISA added CVE-2026-20349 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-08-11 in the same batch as CVE-2026-68820 (Microsoft Windows Ancillary Function Driver for WinSock use-after-free) and CVE-2026-72898 (Metabase SQL injection), triggering a Binding Operational Directive 22-01 remediation deadline of 2026-08-14 for U.S. federal civilian executive branch agencies. Cisco has released hotfixes for every affected ASA (9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and FTD (7.0, 7.2, 7.4, 7.6, 7.7, 10.0) release train; no workaround exists, so organizations that cannot immediately hotfix must accept risk or disable the vulnerable remote-access service. Given ASA/FTD's history as a repeatedly and actively targeted edge-VPN platform, defenders should treat any unexpected reload of an internet-facing ASA/FTD appliance with RA VPN, IKEv2, or ZTNA enabled as a potential CVE-2026-20349 exploitation event pending further Cisco guidance.

MITRE ATT&CK techniques used in TL-2026-1993

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499 Endpoint Denial of Service; T1499.004 Endpoint Denial of Service

Resource Development

T1583 Acquire Infrastructure; T1587.004 Develop Capabilities; T1588 Obtain Capabilities; T1588.005 Obtain Capabilities; T1588.006 Obtain Capabilities

Reconnaissance

T1590 Gather Victim Network Information; T1590.006 Gather Victim Network Information; T1592 Gather Victim Host Information; T1592.002 Gather Victim Host Information; T1592.004 Gather Victim Host Information; T1595 Active Scanning; T1595.001 Active Scanning; T1595.002 Active Scanning

Affected products and versions in Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349)

  • Cisco — Secure Firewall Adaptive Security Appliance (ASA) Software
    Vulnerable versions: 9.16; 9.18; 9.20; 9.22; 9.23; 9.24
    Fixed in: 89.16.4.50; 89.18.4.50; 9.20.4.235; 9.22.3.191; 9.23.1.211; 9.24.1.221
  • Cisco — Secure Firewall Threat Defense (FTD) Software
    Vulnerable versions: 7.0; 7.2; 7.4; 7.6; 7.7; 10.0
    Fixed in: Hotfix per release train via Cisco Software Checker

Remediation for Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349)

Patches

  • ASA 9.16 -> 89.16.4.50
  • ASA 9.18 -> 89.18.4.50
  • ASA 9.20 -> 9.20.4.235
  • ASA 9.22 -> 9.22.3.191
  • ASA 9.23 -> 9.23.1.211
  • ASA 9.24 -> 9.24.1.221
  • FTD 7.0 / 7.2 / 7.4 / 7.6 / 7.7 / 10.0 -> hotfix identified per-platform via the Cisco Software Checker tool

Immediate actions

  • Apply the Cisco-provided hotfix matching your exact ASA/FTD release train immediately — no workaround exists
  • If hotfixing cannot happen immediately, restrict or disable internet exposure of Remote Access SSL VPN (webvpn), IKEv2 RA VPN client services, and FTD Zero Trust Network Access on affected appliances
  • Deploy Cisco Snort detection rules SID 46897 and SID 59654 (published with the advisory) to alert on crafted-HTTP-request exploitation attempts against the Remote Access SSL VPN service
  • U.S. federal civilian agencies must remediate per CISA BOD 22-01 by the 2026-08-14 KEV deadline
  • Monitor affected appliances for unexpected/unscheduled reloads and correlate with VPN service logs

Workarounds

  • None available — Cisco confirms there is no workaround; disabling the vulnerable remote-access feature is the only mitigation short of applying the hotfix

Longer-term hardening

  • Subscribe to Cisco PSIRT advisories for ASA/FTD and track the recurring pattern of actively-exploited edge-VPN vulnerabilities on this platform
  • Implement out-of-band management and network segmentation for firewall/VPN administrative and remote-access interfaces
  • Establish an accelerated patch-validation workflow specifically for internet-facing VPN concentrators given repeated KEV-listed ASA/FTD flaws

CVEs associated with Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349)

CVE-2026-20349

Weaknesses (CWE) in Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349)

CWE-244

Timeline of Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349)

  • The Hacker News reports the ASA/FTD flaw as exploited in the wild to trigger remote DoS, corroborating the Cisco advisory and KEV listing.
  • BleepingComputer reports affected version ranges, CVSS 8.6 score, and the vulnerable-configuration requirements (IKEv2 RA VPN, SSL VPN, FTD ZTNA), and notes the advisory withholds indicators of compromise.
  • CVE-2026-20349 record published at 17:06 UTC with CVSS 3.1 score 8.6 and CWE-244 classification.
  • CISA adds CVE-2026-20349 to the Known Exploited Vulnerabilities catalog alongside CVE-2026-68820 (Windows AFD use-after-free) and CVE-2026-72898 (Metabase SQL injection).
  • Cisco releases hotfixes for all affected ASA (9.16-9.24) and FTD (7.0-7.7, 10.0) release trains; no workaround is made available.
  • Cisco publishes Snort detection rules SID 46897 and SID 59654 alongside the advisory to help defenders detect exploitation attempts against the Remote Access SSL VPN service.
  • Cisco PSIRT confirms it became aware of active in-the-wild exploitation of CVE-2026-20349, without disclosing attacker identity, targeted organizations/sectors, or any indicators of compromise.
  • Cisco publishes Security Advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF disclosing CVE-2026-20349, discovered internally and independently reported by researcher Valerio Brussani.
  • Canadian Centre for Cyber Security publishes advisory AL26-018/AV26-807, recommending log review for unexpected device reloads and anomalous HTTP requests.
  • French CERT-FR publishes advisory CERTFR-2026-AVI-1010 covering CVE-2026-20349.
  • SecurityWeek covers the Cisco advisory and CISA KEV addition, noting Cisco disclosed neither a public CVSS score at initial report time nor any IOCs.
  • Penligent HackingLabs and Cataam independently confirm no weaponized public proof-of-concept exists for CVE-2026-20349; Penligent notes the observed exploitation occurred at or before public disclosure, indicating the in-the-wild actor(s) used an independently developed or privately obtained exploit.
  • Security Arsenal and Cataam publish independent detection-and-remediation guides, including specific syslog message IDs (101001, 101002, 111008, 199013), a connection-burst SIEM correlation heuristic, and HA failover-pair patch-validation guidance.
  • Help Net Security and SecurityWeek publish independent writeups; Help Net Security identifies active SSL listen sockets as a precondition for exploitability, and SecurityWeek contextualizes this as the 12th Cisco-product CVE added to CISA's KEV catalog in 2026.
  • Qualys ThreatPROTECT publishes technical analysis and detection guidance, including QIDs 317873 and 317874 for identifying vulnerable ASA/FTD assets.
  • CISA Binding Operational Directive 22-01 deadline: U.S. federal civilian executive branch agencies must apply the CVE-2026-20349 hotfix or disable the vulnerable service.

Update history for TL-2026-1993

Sources cited for Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349)

Threats related to Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349)

Detection coverage for TL-2026-1993

As of 2026-08-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1993 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats