Full research report

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Original reporting โ†—
โ˜… Threat intelligence assessment high confidence

Executive assessment

The strongest evidence is Cisco's 11 August advisory, which explicitly confirms active exploitation and identifies the attack surface as Remote Access SSL VPN HTTP processing on suitably configured ASA and FTD devices. CISA's same-day KEV listing independently elevates the issue from technical possibility to observed exploitation, despite the comparatively limited published impact of device reload and service denial. Exposure is configuration-dependent, but Cisco provides no workaround, making the correct release- and platform-specific hot fix the primary control. Public reporting contains no actor, victim, campaign or request-signature details, and no public repository matching the CVE was found. Defenders should therefore prioritise exposed VPN appliances, patch promptly and use reload, crash and VPN-interruption telemetry to look retrospectively for possible exploitation.

What happened

Cisco published an advisory for CVE-2026-20349 on 11 August 2026 and said its Product Security Incident Response Team became aware of active exploitation during August. The vulnerability permits an unauthenticated remote attacker to make an affected ASA or FTD device reload, causing denial of service. CISA added it to the Known Exploited Vulnerabilities catalogue on the same day and set 14 August 2026 as the federal remediation deadline.

Affected scope

Vulnerable Cisco Secure Firewall ASA or FTD releases are exposed when IKEv2 Remote Access VPN with client services, SSL VPN, or, on FTD, Zero Trust Network Access enables the relevant SSL listening socket. Cisco lists hot fixes for ASA trains 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24 and FTD trains 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0; Cisco Secure Firewall Management Center is confirmed not vulnerable.

Technical assessment

Cisco attributes the condition to insufficient error checking while the Remote Access SSL VPN service processes HTTP requests. A specially formed request can cause an unexpected device reload without authentication, interrupting firewall or remote-access availability; the published CVSS 3.1 vector rates availability impact as high and confidentiality and integrity impact as none. The public records do not establish code execution, data theft or authentication bypass.

Recommended defensive actions

  1. Inventory ASA and FTD devices, software trains and enabled IKEv2 client-services, SSL VPN and Zero Trust Network Access configurations, prioritising internet-exposed interfaces.
  2. Apply Cisco's release- and platform-specific ASA or FTD hot fix immediately; no workaround addresses the vulnerability.
  3. Verify successful installation and supported upgrade compatibility, including Cisco's stated ASDM requirement for ASA hot fixes whose release numbers begin with 89.
  4. Monitor device reloads, crash records, VPN interruptions and anomalous HTTP activity directed at exposed remote-access SSL VPN listeners.
  5. Review telemetry from before patching for unexplained reloads and preserve relevant logs and crash information for investigation.

Uncertainties and evidence gaps

  • Cisco and CISA have not disclosed the threat actor, targeted organisations or sectors, request patterns, campaign scale or whether attacks achieved effects beyond denial of service.
  • No public proof-of-concept or exploit repository was found, so the availability and circulation of private exploit tooling remain unknown.
  • CISA labels the issue a heap-inspection vulnerability mapped to CWE-244, while Cisco's operational description emphasises insufficient HTTP error checking; the public advisory does not explain this taxonomy relationship.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessUnauthenticated network access to an affected device's enabled Remote Access SSL VPN listening service.
ComponentCisco Secure Firewall ASA or FTD Remote Access SSL VPN HTTP-processing boundary.
MechanismInsufficient error checking when the service processes a specially formed HTTP request can destabilise the device.
ImpactUnexpected firewall reload and resulting denial of service, including interruption to remote-access connectivity.
DetectionMonitor for unexpected ASA or FTD reloads, crash records, VPN outages and anomalous HTTP requests to exposed SSL VPN listeners; Cisco's advisory also links Snort rules 46897 and 59654.
MitigationInstall the exact Cisco hot fix applicable to the ASA or FTD release and hardware platform; Cisco states that no workaround addresses the flaw.
Exploitation status

Confirmed active exploitation in August 2026; no public proof-of-concept or exploit repository was identified during this investigation.

The investigation began by testing the report's central claims: whether CVE-2026-20349 affects Cisco ASA and FTD, whether exploitation is current, and whether fixes or public exploit code exist. Cisco's advisory established the affected service, configurations, impact, active exploitation and hot fixes, while CISA, NVD and the CVE record corroborated the vulnerability and exploitation status. A repository search found no public project matching the CVE, but that does not exclude unpublished or privately circulated tooling.

  1. What claims did the supplied article make about the event?
    Opened and reviewed the supplied report dated 12 August 2026.
    thehackernews.com โ†—

    The article attributed an unauthenticated remote denial of service, active exploitation and release-specific fixes to Cisco, while reporting no known actor or victim details.

    why This framed the claims requiring confirmation but was treated as secondary reporting rather than proof.

  2. Had CISA independently classified the vulnerability as exploited?
    Opened CISA's filtered Known Exploited Vulnerabilities catalogue entry.
    cisa.gov โ†—

    CISA lists CVE-2026-20349 as known exploited, added it on 11 August 2026 and assigned a 14 August 2026 remediation deadline.

    why This independently corroborated exploitation and made remediation an immediate operational priority.

  3. What technical description and severity are recorded by NVD?
    Opened the National Vulnerability Database record.
    nvd.nist.gov โ†—

    NVD records unauthenticated remote exploitation through the SSL VPN service, unexpected device reload, CVSS 8.6 and inclusion in CISA KEV.

    why This corroborated the availability impact and showed that the published score does not imply confidentiality or integrity compromise.

  4. What does Cisco itself confirm about exposure, exploitation and remediation?
    Opened and read Cisco's full security advisory, including affected configurations, fixed software and exploitation sections.
    sec.cloudapps.cisco.com โ†—

    Cisco confirms active exploitation in August 2026, exposure through enabled IKEv2 client services, SSL VPN or FTD Zero Trust Network Access, no workaround, and hot fixes for affected ASA and FTD trains.

    why The vendor advisory is the strongest source for product scope and remediation and establishes that patching, rather than configuration mitigation, is required for full remediation.

  5. Does the authoritative CVE record agree with Cisco's technical account?
    Opened the CVE programme record assigned by Cisco.
    cve.org โ†—

    The record confirms the SSL VPN HTTP-processing condition, unauthenticated remote denial of service, CVSS 8.6 and CWE-244 mapping.

    why This validated the CVE identity and exposed a taxonomy nuance: CWE-244 is used even though the narrative focuses on insufficient error checking.

  6. Is readily discoverable public proof-of-concept code available?
    Queried GitHub's public repository search for the exact CVE identifier.
    api.github.com โ†—

    The search returned zero matching repositories at the time of review.

    why This supports reporting that no public repository was identified, but it cannot prove that exploit code does not exist elsewhere or privately.

TargetsInternet-exposed Cisco Secure Firewall ASA devicesInternet-exposed Cisco Secure Firewall Threat defence devicesOrganisations using affected remote-access VPN or Zero Trust Network Access configurations
Related CVEs CVE-2026-20349

Research coverage

All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 10 registered sources supplied useful evidence (2 primary, 7 corroborating, 1 contextual and 0 PoC/exploit references). 51 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked โ€” no match Unavailable Failed Disabled
Complete source-by-source audit 68 sources
SourceRun resultValueWhy it was useful โ€” or not
CISA KEVkev ok1665 records Primary evidence2 matched items Confirmed that a related CVE is listed in CISA's Known Exploited Vulnerabilities catalogue. Supplied a vendor or government advisory opened and verified during focused research.
The Hacker Newsnews ok10 records Primary evidence1 matched items Published the source report used to frame and date the event.
CISA Alertsnews ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
GitHub topic: cveresearch ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
GitHub topic: exploitresearch ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
GitHub topic: penetration-testingresearch ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
GitHub topic: pocresearch ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
GitHub topic: vulnerabilityresearch ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
NVDcve ok900 records Corroborating1 matched items Supplied independent analysis opened and verified during focused research.
FIRST EPSSepss ok7602 records Context1 matched items Added exploitation-probability context; EPSS does not itself prove exploitation.
AlienVault OTXdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
BleepingComputernews ok11 records Checked โ€” no match The source completed, but none of its retained records matched this story.
CIRCL CVEcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5324 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Discorddeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI exploitsdeepdarkcti ok24 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI forumsdeepdarkcti ok264 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware samplesdeepdarkcti ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI marketsdeepdarkcti ok127 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI phishingdeepdarkcti ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI ransomware gangsdeepdarkcti ok682 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI RATsdeepdarkcti ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1008 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Checked โ€” no match The source completed, but none of its retained records matched this story.
DNSDumpster domain IOC enrichmentresearch ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GreyNoiseexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok8 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok12 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok13 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1590 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
MISP threat actor galaxyactor ok0 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked โ€” no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Rapid7news ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Shodanresearch ok6 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Sigma Rulesresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
ThreatFoxthreat_intelligence ok100 records Checked โ€” no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Unit42 IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Additional verified pages 13 opened outside the registered collection
Vulnerability & exploitation2
CVE-2026-20349 CISA KEV Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) ยท added 2026-08-11 CISA catalog โ†—
CVE-2026-20349 EPSS 1.0% 59th percentile exploitation probability
Vendor & gov advisories2
Cisco Secure Firewall ASA and FTD Remote Access SSL VPN Denial of Service Vulnerability sec.cloudapps.cisco.com โ†—

Cisco confirms active exploitation, identifies vulnerable configurations and provides release-specific hot fixes.

CISA Known Exploited Vulnerabilities entry for CVE-2026-20349 cisa.gov โ†—

CISA added the flaw on 11 August 2026 with a federal remediation deadline of 14 August 2026.

Analysis & research3
NVD record for CVE-2026-20349 nvd.nist.gov โ†—

Independently records the unauthenticated remote denial-of-service impact, CVSS 8.6 rating and KEV status.

CVE record for CVE-2026-20349 cve.org โ†—

Confirms the Cisco-assigned description, affected SSL VPN service, CWE-244 mapping and CVSS vector.

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS thehackernews.com โ†—

Secondary reporting summarises the advisory and notes that victim and threat-actor details remain undisclosed.