Skip to content
feed: live
>_ 0dayNews
cisco
● Breaking

Cisco ASA/FTD VPN Flaw Exploited, CISA Sets Aug 14 Deadline

CVE-2026-20349 added to CISA KEV today. Unauthenticated attackers can crash Cisco ASA and FTD devices over VPN — CISA's due date is August 14.

Cisco ASA/FTD VPN Flaw Exploited, CISA Sets Aug 14 Deadline
Photo: Adamantios / Wikimedia Commons · CC BY-SA 3.0
fuse Marisol "Fuse" Delgado · Published · 2 min read

CISA added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog today, confirming active exploitation of a heap inspection flaw in Cisco Secure Firewall ASA and FTD software. BleepingComputer reports that attackers are remotely crashing affected devices via VPN. CISA’s remediation deadline for federal agencies is August 14 — three days from now.

That is your firewall going offline. A denial-of-service against a VPN concentrator takes remote access down and, depending on fail-open configuration, can gap your perimeter enforcement. Active exploitation is confirmed — CISA doesn’t add to KEV on suspicion.

What the Flaw Does

CVE-2026-20349 is a heap inspection vulnerability in the VPN processing code shared between Cisco Secure Firewall ASA and FTD platforms. An unauthenticated remote attacker can send crafted input that causes the affected process to fault and the device to reload — a full, unexpected reboot of your firewall appliance.

CVSS 8.6, rated high. The score reflects unauthenticated remote exploitability combined with confirmed real-world exploitation. The impact here is availability, not code execution — but availability of a perimeter firewall is not optional in any environment.

Affected Products

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) are both affected. Check the Cisco advisory — linked from the NVD record — for specific affected software version ranges and corrected builds. Patch to the exact listed builds. Don’t assume adjacent releases are covered without verifying.

What to Do

  1. Apply Cisco’s fix. The Cisco advisory identifies affected versions and the corrected builds. Target August 14 as your deadline regardless of whether you’re a federal entity — if CISA is treating this as a three-day window, that’s the pace active exploitation demands.

  2. Review crash logs for pre-patch activity. Anomalous device reloads on ASA or FTD units handling VPN traffic are a potential exploitation indicator. If you’re seeing unexplained reboots in your firewall event log, don’t wait until after you patch to investigate — start the review now.

  3. Internet-facing ASA and FTD units are your highest priority. Any Cisco firewall processing untrusted VPN connections from outside your network is the exposed surface. Internal-only deployments carry lower urgency but stay in the patch queue.

This hits the same day as August 2026 Patch Tuesday — a 400-plus CVE Microsoft cycle with its own actively exploited zero-day. Pick order: Cisco ASA/FTD if you’re running exposed VPN infrastructure; the Microsoft exploited zero-day alongside it.

This is also the third Cisco KEV addition in recent weeks — CVE-2026-20316 in Firewall Management Center was confirmed exploited on July 29. The pattern matters for prioritization: Cisco network infrastructure is an active target category right now, not a background noise item.

Track all CISA-confirmed actively exploited CVEs on the KEV tracker.

Related CVEs
  • [ HIGH ] CVE-2026-20349 Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw

Found this useful? Share it.