Cisco Addresses Critical Vulnerability (CVE-2026-20349) Exposing Firewall DoS Risk

www.news4hackers.com-cisco-addresses-critical-vulnerability-cve-2026-20349-exposing-firewall-dos-risk-cisco-addresses-critical-vulnerability-cve-2026-20349-exposing-firewall-dos-risk

Cisco addresses critical flaw enabling denial-of-service attacks on firewall systems (CVE-2026-20349)

Vulnerability Details

A critical security flaw (CVE-2026-20349) has been actively exploited to disrupt Cisco firewall operations, according to official disclosures.

The vulnerability has been included in CISA’s Known Exploited Vulnerabilities list, requiring immediate mitigation for US civilian federal agencies by August 14, 2026. Specific attack details remain undisclosed. Cisco’s Product Security Incident Response Team (PSIRT) confirmed awareness of ongoing exploitation of this flaw in August 2026. The vulnerability impacts the Remote Access SSL VPN service within Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Affected components include IKEv2 Remote Access VPN (with client services), SSL VPN, and Zero Trust Network Access (ZTNA). Devices are susceptible if they operate with affected software versions and have these features enabled, specifically when SSL listen sockets are active.

Attackers can trigger the flaw through a specially crafted HTTP request targeting the vulnerable service, causing security appliances to reboot unexpectedly and creating a denial-of-service condition. The exploit does not require authentication or user interaction.

Mitigation Steps

Cisco has released hot fixes for ASA software versions 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, as well as FTD software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. No workarounds exist, and no indicators of compromise have been identified.

Discovery and Reporting

The vulnerability was discovered during internal security testing by Cisco and independently reported by security researcher Valerio Brussani. The flaw enables remote execution of malicious payloads without authentication, posing significant risks to network availability. Affected organizations are advised to apply the provided patches immediately to prevent potential service disruptions.


Blog Image

About Author

en_USEnglish