
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20349 is a denial-of-service (DoS) vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. The flaw allows an unauthenticated, remote attacker to cause the affected device to reload unexpectedly by sending a crafted HTTP request. It was publicly disclosed on August 11, 2026, and affects a wide range of ASA software versions (9.16.x through 9.24.x) and FTD software versions (7.0.x through 10.0.x). The vulnerability carries a CVSS v3.1 base score of 8.6 (High) (Cisco Advisory, CISA KEV).
The vulnerability is classified as CWE-244 (Improper Clearing of Heap Memory Before Release / 'Heap Inspection'), arising from insufficient error checking when processing HTTP requests directed at the Remote Access SSL VPN service. The attack vector is network-based, requires no authentication or user interaction, and has a changed scope, meaning the impact extends beyond the vulnerable component itself. Exploitation is triggered by sending a specially crafted HTTP request to the SSL VPN listener on an affected device, causing an unexpected process crash and device reload. The vulnerability affects devices configured with SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access (ZTNA) features that enable SSL listen sockets (Cisco Advisory). Cisco Bug ID CSCwv96220 tracks this issue, and Snort rules 46897 and 59654 have been published for detection.
Successful exploitation results in an unexpected device reload, causing a complete denial of service for all traffic passing through the affected Cisco firewall. Because these devices typically serve as network perimeter security controls, a successful DoS attack can disrupt VPN connectivity, remote access services, and all network traffic dependent on the firewall, potentially affecting entire organizations. There is no reported confidentiality or integrity impact; however, repeated exploitation could sustain prolonged outages and may be used to disrupt security controls as a precursor to broader attacks (Cisco Advisory, CISA KEV).
CVE-2026-20349 is being actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 11, 2026, with a remediation due date of August 14, 2026 (CISA KEV). Cisco's PSIRT confirmed active exploitation in August 2026, and the vulnerability was also independently reported by researcher Valerio Brussani (Cisco Advisory). No public proof-of-concept exploit code has been confirmed, though exploitation has been widely reported across multiple threat intelligence sources. The EPSS score is approximately 0.874%, and the vulnerability is marked as automatable with active exploitation status by NVD SSVC. The CISA KEV entry notes the vulnerability's potential use in ransomware campaigns is currently unknown.
%ASA-1-104001: (Primary) Switching to ACTIVE - Service card in other unit has failed); crash dump files generated around the time of the reload; syslog entries indicating process failures in the SSL VPN or webvpn subsystem.Cisco has released hot fixes for affected ASA and FTD software versions. For ASA, hot fixes are available for releases 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24 (e.g., ASA 9.20.4.235, 9.22.3.191, 9.23.1.211, 9.24.1.221). For FTD, hot fixes are available for releases 7.0 (7.0.9.1-1), 7.2 (7.2.11.1-2), 7.4 (7.4.7.1-1), 7.6 (7.6.4.1-2), 7.7 (7.7.11.1-2), and 10.0 (10.0.0.1-2). Cisco confirms there are no workarounds available for this vulnerability. Organizations should prioritize immediate patching, especially for devices with SSL VPN, IKEv2 Remote Access VPN, or ZTNA features exposed to untrusted networks, and should restrict network access to the SSL VPN service to authorized users where possible (Cisco Advisory, CISA KEV).
Cisco's PSIRT issued a formal advisory on August 11, 2026, confirming active exploitation and strongly recommending immediate upgrades (Cisco Advisory). CISA added the vulnerability to its KEV catalog the same day with a three-day remediation deadline, reflecting the urgency of the threat (CISA KEV). The vulnerability received broad coverage from major security outlets including The Hacker News, SecurityWeek, BleepingComputer, and Help Net Security, with community discussion active on Reddit's r/SecOpsDaily and r/CVEWatch. Water-ISAC issued a TLP:CLEAR vulnerability notification, and government CERTs in Hong Kong, Canada, and Portugal published advisories. Eclypsium published a detailed technical blog post titled "CVE-2026-20349: Someone is Crashing Cisco Firewalls — We Need to Talk About Why," drawing significant attention to the broader implications of the flaw.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."