Skip to content
feed: live
>_ 0dayNews
CVE Record
[ HIGH ] CVE-2026-20349

Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw

Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.

cat cve-2026-20349.json
Vendor
Cisco
Product
Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CVSS
8.6
EPSS (exploit probability)
N/A
Status
kev
Published

CVE-2026-20349 is a heap inspection vulnerability in the VPN processing code shared between Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). An unauthenticated, remote attacker can send crafted input to exploit the flaw, causing the affected device to reload unexpectedly — a full denial-of-service condition.

CISA added this CVE to the Known Exploited Vulnerabilities catalog on August 11, 2026, confirming active exploitation in the wild. The federal remediation deadline is August 14, 2026 under BOD 26-04.

Affected: Cisco Secure Firewall ASA and Secure Firewall Threat Defense (FTD) — check the Cisco advisory linked from the NVD record for specific affected software version ranges and corrected builds.

Action: Apply Cisco’s patched builds immediately. Internet-facing ASA and FTD devices processing untrusted VPN connections are the highest-priority exposure. Review firewall event logs for anomalous device reload events that may indicate pre-patch exploitation.

See full coverage: Cisco ASA/FTD VPN Flaw Exploited, CISA Sets Aug 14 Deadline.