HackMyIP
← Back to News
2026-08-12 The Hacker News

Cisco ASA and FTD Flaw (CVE-2026-20349) Actively Exploited for DoS

VulnerabilityThreat IntelIncident Response

Cisco has confirmed that a high-severity vulnerability in Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software is being actively exploited in the wild. Tracked as CVE-2026-20349 and carrying a CVSS score of 8.6, the flaw stems from insufficient error checking when the affected platforms process HTTP requests, enabling an unauthenticated remote attacker to trigger a denial-of-service condition on the target device. According to Cisco's Tuesday advisory, exploitation involves sending a crafted HTTP request to the Remote Access SSL VPN service, which can force the appliance to reload and disrupt network operations.

The vulnerability affects organizations running vulnerable versions of ASA or FTD Software with one or more of the following configurations enabled: IKEv2 Remote Access VPN with client services (`crypto ikev2 enable client-services port `), SSL-VPN via `webvpn enable `, or Zero Trust Network Access 2 via `zero-trust enable`. Because the attack requires no authentication and only network reachability to the VPN interface, internet-exposed Cisco VPN gateways are particularly attractive targets for opportunistic threat actors and state-sponsored groups alike.

Cisco has shipped patches across multiple release branches, including ASA 9.16 (9.16.4.50), 9.18 (9.18.4.50), 9.20 (9.20.4.235), 9.22 (9.22.3.19), 9.23 (9.23.1.21), and 9.24 (9.24.1.22), alongside hotfix bundles for FTD 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Network defenders should prioritize patching immediately and review perimeter exposure of any SSL VPN listeners, validate certificate hygiene with an SSL/TLS checker, and audit publicly reachable interfaces using a port scanner to confirm only intended services are exposed. To harden remote access posture and detect misconfigurations, admins can also validate egress and tunneling behavior with a VPN/proxy detector and ensure compromised credentials have not been reused by reviewing accounts against our email breach checker.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →