HackMyIP
← Back to News
2026-08-12 SecurityWeek

Cisco Patches Firewall Zero-Day CVE-2026-20349 Exploited for DoS Attacks

Zero-DayVulnerability

Cisco released emergency patches on Tuesday for a zero-day vulnerability, tracked as CVE-2026-20349, affecting firewalls running Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. The flaw resides in the processing of HTTP requests and enables a remote, unauthenticated attacker to trigger an appliance reload, forcing it into a denial-of-service (DoS) condition. All an attacker needs is a specially crafted HTTP request aimed at the Remote Access SSL VPN service, making exploitation trivial against any unpatched perimeter device.

The vulnerability was discovered internally by Cisco and independently reported by an external researcher. Cisco confirmed it became aware of active exploitation in August 2026, though the company has not disclosed any technical details about the threat actors or campaigns leveraging CVE-2026-20349. Disrupting a security appliance is particularly dangerous for enterprise defenses, as a knocked-out firewall can create a blind spot that enables further lateral movement, data exfiltration, or ransomware deployment. Network defenders can validate exposure of their own VPN gateways using our SSL/TLS checker to confirm hardened configurations and certificate integrity.

CISA added CVE-2026-20349 to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, directing U.S. federal agencies to apply patches by August 14 under BOD 22-01. This marks the 12th Cisco product bug with a 2026 CVE identifier added to the KEV list this year, with most prior entries tied to SD-WAN product flaws, alongside previously exploited Unified CM and FMC vulnerabilities. Cisco has urged all customers to apply the available hotfixes immediately, especially given that successful DoS attacks on security infrastructure often precede follow-on intrusions. Administrators responsible for perimeter appliances should also audit exposed management interfaces and VPN listeners using a port scanner to ensure no shadow services are reachable from the internet.

The disclosure follows closely on related advisories from Cisco warning of high-severity ClamAV vulnerabilities with public proof-of-concept code and critical SD-WAN, IOS XE, and FMC flaws. With Microsoft also publishing its August 2026 Patch Tuesday covering 421 CVEs including one actively exploited zero-day, security teams face a heavy remediation cycle. Organizations running affected Cisco ASA or FTD appliances should prioritize CVE-2026-20349 patching, hunt for indicators of pre-exploitation reconnaissance, and review VPN logs for anomalous HTTP request patterns targeting their gateways.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Password Checker →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

Password security basics →Two-factor authentication explained →How to create a strong password →