Cisco Fixes Zero-Day Firewall Vulnerability Used in DoS Attacks
Cisco notified its clients on Tuesday that it has issued updates to resolve a critical flaw impacting firewalls utilizing Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software.
Overview of the Vulnerability
The vulnerability, designated CVE-2026-20349, involves improper handling of HTTP requests. A remote attacker without authentication credentials could trigger a device reboot, resulting in a denial-of-service (DoS) condition, by transmitting a maliciously crafted HTTP request to the Remote Access SSL VPN service. The issue was identified internally by Cisco and independently reported by an external researcher.
Exploitation and Response
Cisco confirmed awareness of ongoing exploitation of CVE-2026-20349 in August 2026 but has not disclosed specific details about the attacks. Such vulnerabilities pose risks to threat actors seeking to compromise security infrastructure, potentially disrupting operations. Cisco has advised users to implement the provided hotfixes promptly.
CISA Inclusion and Compliance
The Cybersecurity and Infrastructure Security Agency (CISA) included CVE-2026-20349 in its Known Exploited Vulnerabilities (KEV) list on Tuesday, mandating federal agencies to apply the patch by August 14.
Broader Implications
This marks the 12th Cisco-related vulnerability with a 2026 CVE identifier added to the KEV catalog this year. While most entries pertain to SD-WAN product flaws, adversaries have also targeted Unified CM and FMC vulnerabilities.
