CVE-2026-20349
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2026-20349 is a denial-of-service (DoS) vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. The flaw allows an unauthenticated, remote attacker to cause the affected device to reload unexpectedly by sending a crafted HTTP request. It was publicly disclosed on August 11, 2026, and affects a wide range of ASA software versions (9.16.x through 9.24.x) and FTD software versions (7.0.x through 10.0.x). The vulnerability carries a CVSS v3.1 base score of 8.6 (High) (Cisco Advisory, CISA KEV).

Technical details

The vulnerability is classified as CWE-244 (Improper Clearing of Heap Memory Before Release / 'Heap Inspection'), arising from insufficient error checking when processing HTTP requests directed at the Remote Access SSL VPN service. The attack vector is network-based, requires no authentication or user interaction, and has a changed scope, meaning the impact extends beyond the vulnerable component itself. Exploitation is triggered by sending a specially crafted HTTP request to the SSL VPN listener on an affected device, causing an unexpected process crash and device reload. The vulnerability affects devices configured with SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access (ZTNA) features that enable SSL listen sockets (Cisco Advisory). Cisco Bug ID CSCwv96220 tracks this issue, and Snort rules 46897 and 59654 have been published for detection.

Impact

Successful exploitation results in an unexpected device reload, causing a complete denial of service for all traffic passing through the affected Cisco firewall. Because these devices typically serve as network perimeter security controls, a successful DoS attack can disrupt VPN connectivity, remote access services, and all network traffic dependent on the firewall, potentially affecting entire organizations. There is no reported confidentiality or integrity impact; however, repeated exploitation could sustain prolonged outages and may be used to disrupt security controls as a precursor to broader attacks (Cisco Advisory, CISA KEV).

Exploitability

CVE-2026-20349 is being actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 11, 2026, with a remediation due date of August 14, 2026 (CISA KEV). Cisco's PSIRT confirmed active exploitation in August 2026, and the vulnerability was also independently reported by researcher Valerio Brussani (Cisco Advisory). No public proof-of-concept exploit code has been confirmed, though exploitation has been widely reported across multiple threat intelligence sources. The EPSS score is approximately 0.874%, and the vulnerability is marked as automatable with active exploitation status by NVD SSVC. The CISA KEV entry notes the vulnerability's potential use in ransomware campaigns is currently unknown.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Cisco ASA or FTD devices with Remote Access SSL VPN, IKEv2 VPN with client services, or Zero Trust Network Access enabled, using tools such as Shodan or Censys targeting Cisco firewall banners on HTTPS ports (typically 443).
  2. Confirm vulnerable configuration: Verify the target is running a vulnerable ASA version (9.16.x–9.24.x) or FTD version (7.0.x–10.0.x) with SSL listen sockets active, which can be inferred from service banners or known version fingerprinting.
  3. Craft malicious HTTP request: Construct a specially crafted HTTP request designed to trigger insufficient error handling in the SSL VPN HTTP processing code, exploiting the heap inspection flaw (CWE-244).
  4. Send request to SSL VPN service: Deliver the crafted HTTP request to the target device's SSL VPN listener (typically TCP/443), requiring no authentication or prior session establishment.
  5. Trigger device reload: The malformed request causes the device to crash and reload unexpectedly, resulting in a DoS condition that disrupts all firewall-dependent network traffic and VPN services (Cisco Advisory).

Indicators of compromise

  • Network: Unexpected or repeated HTTPS requests to the SSL VPN service (port 443) from external or unknown IP addresses, particularly with malformed or anomalous HTTP headers or payloads; sudden loss of connectivity through the firewall.
  • Logs: Cisco ASA or FTD system logs showing unexpected device reload events (e.g., %ASA-1-104001: (Primary) Switching to ACTIVE - Service card in other unit has failed); crash dump files generated around the time of the reload; syslog entries indicating process failures in the SSL VPN or webvpn subsystem.
  • Device Behavior: Repeated unplanned device reboots without administrative action; VPN sessions dropping unexpectedly; firewall management interface becoming temporarily unreachable following reload events.
  • SIEM/IDS: Alerts from Snort rules 46897 and 59654 published by Cisco for this vulnerability (Cisco Advisory).

Mitigation and workarounds

Cisco has released hot fixes for affected ASA and FTD software versions. For ASA, hot fixes are available for releases 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24 (e.g., ASA 9.20.4.235, 9.22.3.191, 9.23.1.211, 9.24.1.221). For FTD, hot fixes are available for releases 7.0 (7.0.9.1-1), 7.2 (7.2.11.1-2), 7.4 (7.4.7.1-1), 7.6 (7.6.4.1-2), 7.7 (7.7.11.1-2), and 10.0 (10.0.0.1-2). Cisco confirms there are no workarounds available for this vulnerability. Organizations should prioritize immediate patching, especially for devices with SSL VPN, IKEv2 Remote Access VPN, or ZTNA features exposed to untrusted networks, and should restrict network access to the SSL VPN service to authorized users where possible (Cisco Advisory, CISA KEV).

Community reactions

Cisco's PSIRT issued a formal advisory on August 11, 2026, confirming active exploitation and strongly recommending immediate upgrades (Cisco Advisory). CISA added the vulnerability to its KEV catalog the same day with a three-day remediation deadline, reflecting the urgency of the threat (CISA KEV). The vulnerability received broad coverage from major security outlets including The Hacker News, SecurityWeek, BleepingComputer, and Help Net Security, with community discussion active on Reddit's r/SecOpsDaily and r/CVEWatch. Water-ISAC issued a TLP:CLEAR vulnerability notification, and government CERTs in Hong Kong, Canada, and Portugal published advisories. Eclypsium published a detailed technical blog post titled "CVE-2026-20349: Someone is Crashing Cisco Firewalls — We Need to Talk About Why," drawing significant attention to the broader implications of the flaw.

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20349HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
YesYesAug 11, 2026
CVE-2026-20012HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesMar 25, 2026
CVE-2026-20025MEDIUM6.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20023MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20024MEDIUM5.7
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management