Cisco ASA, FTD Critical 0-Day Lets Attackers Trigger DoS
Key Takeaways Cisco has disclosed a critical zero-day vulnerability (CVE-2026-20349) affecting its Adaptive Security Appliance (ASA) and Threat Defense (FTD) firewall software. The flaw, which is...
Key Takeaways
- Cisco has disclosed a critical zero-day vulnerability (CVE-2026-20349) affecting its Adaptive Security Appliance (ASA) and Threat Defense (FTD) firewall software.
- The flaw, which is actively being exploited in the wild, allows unauthenticated remote attackers to trigger a denial-of-service condition by forcing a device reload.
- The vulnerability impacts devices running specific ASA or FTD software versions with SSL VPN, IKEv2 Remote Access VPN, or Zero Trust Network Access features enabled.
- Cisco has released hot fixes and urges immediate patching to mitigate the risk.
Critical Cisco Firewall Zero-Day Under Active Exploitation
Cybersecurity teams overseeing Cisco network edge infrastructure are facing an urgent mandate to patch a newly revealed zero-day vulnerability in the company’s firewall VPN stack. Cisco has confirmed that this critical flaw is already being actively exploited.
Table Of Content
Designated as CVE-2026-20349, the vulnerability targets the Remote Access SSL VPN service within Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Successful exploitation can lead to an unexpected device restart, resulting in a denial-of-service (DoS) state that disrupts remote access and associated network communications.
According to the official Cisco security advisory, the root cause of the vulnerability lies in insufficient error handling when the SSL VPN service processes incoming HTTP requests. A remote attacker, requiring no authentication, can exploit this weakness by sending a specially crafted HTTP request to the Remote Access SSL VPN service on an exposed device.
An attack that succeeds will cause the appliance to reload, severing all active VPN sessions and interrupting any network traffic reliant on the firewall’s continuous operation. Given that many organizations deploy ASA and FTD devices at their network perimeters, even a brief service interruption can severely impact remote workforces, site-to-site connectivity, and other mission-critical applications.
Details of the Cisco Firewall 0-Day Vulnerability
Cisco’s Product Security Incident Response Team (PSIRT) confirmed that it first became aware of “in-the-wild” exploitation of this vulnerability in August 2026. The company is strongly advising customers to prioritize installing fixed software releases over attempting to implement temporary mitigations.
It is important to note that no comprehensive workarounds are available to fully address this vulnerability. The flaw was initially discovered during Cisco’s internal security testing and was also independently reported to the company by researcher Valerio Brussani (@val_brux of harmonyguard.cloud).
Not every Cisco firewall deployment is automatically at risk. Devices are only vulnerable if they are running an affected ASA or FTD software release and have specific features enabled that open SSL listen sockets. These susceptible configurations include:
- SSL VPN with WebVPN enabled on an interface.
- IKEv2 Remote Access VPN with client services.
- On FTD devices only, when the Zero Trust Network Access (ZTNA) feature is active.
Cisco has verified that Cisco Secure Firewall Management Center (FMC) Software is not impacted by this vulnerability. Administrators can determine their exposure by examining their running configurations for WebVPN, IKEv2 client-services, or zero-trust enablement, and by cross-referencing their software versions with Cisco’s Fixed Software guidance.
Cisco has published hot fixes across multiple ASA software trains, including releases within the 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24 branches. Corresponding FTD hot fixes are also available for the 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 lines across all supported platforms. These hot fixes can be downloaded from the Cisco Software Center.
For ASA hot fixes beginning with “89,” Cisco specifies that ASDM Release 7.24.1.374 or later is required for the management interface to correctly interpret the new numbering format. Customers who prefer a complete release upgrade can use the Cisco Software Checker to pinpoint the earliest fixed release compatible with their specific platform and build.
From an operational security perspective, defenders should consider internet-facing SSL VPN listeners as the primary attack vector. Priority should be given to appliances with remote access VPN or zero-trust features enabled, particularly those accessible from untrusted networks.
Following the application of patches, teams should verify VPN availability, review device reload histories, and monitor for any unusual HTTP traffic directed at VPN portals. Cisco’s comprehensive advisory, which includes detailed fixed software tables and configuration verification steps, is available on the Cisco Security Center.
For organizations relying on Cisco ASA or FTD for secure remote access, CVE-2026-20349 serves as a stark reminder that perimeter VPN services remain a prime target for unauthenticated denial-of-service vulnerabilities. Promptly applying vendor hot fixes or upgrading to fixed releases is the only reliable method to eliminate this exposure, especially while active exploitation is underway.
What You Should Do
- Immediately identify all Cisco ASA and FTD devices in your network, especially those exposed to the internet.
- Verify if your devices are running an affected software version and have SSL VPN with WebVPN, IKEv2 Remote Access VPN with client services, or (for FTD) Zero Trust Network Access enabled.
- Prioritize applying the relevant hot fixes or upgrading to a fixed software release as provided by Cisco. Download these from the Cisco Software Center.
- After patching, monitor VPN availability, review device reload logs, and implement enhanced monitoring for unusual HTTP traffic targeting your VPN portals.
- Consult the official Cisco Security Advisory (cisco-sa-asaftd-vpn-dos-dzv4mQFF) for the most up-to-date information, specific version guidance, and detailed mitigation steps.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.