Cisco ASA/FTD VPN DoS, exploited in wild (CVE-2026-20349)
CVE-2026-20349
CVE-2026-20349: Cisco ASA/FTD SSL VPN DoS via crafted HTTP request, actively exploited (CVSS 8.6). Apply Cisco patches or disable Remote Access VPN if unpatched.
Actively exploited in the wild - CVE-2026-20349 is a high-severity denial-of-service (DoS) vulnerability in Cisco Secure Firewall ASA and FTD Software that lets unauthenticated attackers crash the device via a single crafted HTTP request to the Remote Access SSL VPN service. Cisco has confirmed active exploitation; apply vendor updates immediately.
Overview
CVE-2026-20349 affects the Remote Access SSL VPN service on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. The vulnerability stems from insufficient error checking when the device processes HTTP requests. An unauthenticated, remote attacker can trigger an unexpected reload by sending a crafted HTTP request to the SSL VPN portal, causing a denial-of-service condition.
The vulnerability carries a CVSS score of 8.6 (High), with a network attack vector, low attack complexity, no privileges required, and no user interaction needed. CISA has added CVE-2026-20349 to its Known Exploited Vulnerabilities (KEV) catalog, confirming it is being actively exploited in real-world attacks.
Impact on Affected Systems
Successful exploitation results in an unexpected device reload, taking the firewall completely offline. This interrupts all traffic flowing through the device, not just VPN sessions, making the DoS a network-wide availability issue. Since the attack requires no authentication and no user interaction, any attacker with network reachability to the Remote Access SSL VPN service can repeatedly crash the device, creating a persistent availability outage.
Organizations running affected ASA or FTD versions with Remote Access SSL VPN enabled are at immediate risk. Given confirmed in-the-wild exploitation, this vulnerability should be treated as an active threat, not a theoretical risk.
Remediation and Mitigation
Cisco has released software updates addressing CVE-2026-20349. Follow these steps:
- Patch immediately: Upgrade ASA and FTD Software to the latest fixed releases listed in the Cisco Security Advisory. Do not delay, given confirmed exploitation.
- Temporary workaround: If patches cannot be applied immediately, consider disabling the Remote Access SSL VPN service on exposed interfaces or restricting access to the SSL VPN portal via access control lists (ACLs) to trusted IP ranges only.
- Monitor for indicators: Review device logs for unexpected reloads or malformed HTTP requests targeting the SSL VPN service. Correlate with other suspicious activity.
Security Insight
This incident mirrors the pattern seen with Cisco FMC zero-day CVE-2026-20316, where a network perimeter device became an active attack vector. Attackers increasingly target VPN and remote-access infrastructure because it is internet-facing and often runs older, unpatched code. The fact that this flaw sits in the error-handling path of HTTP processing suggests the vendor’s input validation remains a recurring weak point across its security appliance line. As highlighted in the latest weekly threat roundup, VPN-focused exploits remain a top attack vector, and organizations should treat any Cisco remote-access component as a high-value target requiring rigorous patch hygiene. Cisco’s release notes for actively exploited flaws reinforce that this is part of a broader trend of attackers prioritizing firewall and VPN appliances for initial access and disruption.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote...
Microsoft Defender Denial of Service Vulnerability...
An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a denial of service. The vulnerability exists in the GeoNetworking packet processing pipeline where OpenSS...
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-produ...