Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition
Cybersecurity NewsArchived Aug 13, 2026✓ Full text saved
Security teams managing Cisco edge infrastructure face a high-priority patching deadline after Cisco confirmed active exploitation of a newly disclosed zero-day in its firewall VPN stack. Tracked as CVE-2026-20349, the flaw affects the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software […] The post Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition appeared first
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security
Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition
By Guru Baran
August 13, 2026
Security teams managing Cisco edge infrastructure face a high-priority patching deadline after Cisco confirmed active exploitation of a newly disclosed zero-day in its firewall VPN stack.
Tracked as CVE-2026-20349, the flaw affects the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software and can force an unexpected device reload, creating a denial-of-service condition for remote access and related network paths.
According to Cisco’s security advisory, the vulnerability stems from insufficient error checking when the SSL VPN service processes HTTP requests. An unauthenticated remote attacker can exploit the issue by sending a crafted HTTP request to the Remote Access SSL VPN service on an exposed device. No valid credentials are required.
A successful attack causes the appliance to reload, interrupting VPN sessions and any traffic that depends on the firewall remaining online. Because many organizations place ASA and FTD devices at the network perimeter, even a short reload window can disrupt remote workers, site-to-site connectivity, and business-critical applications.
Cisco Firewall 0-Day Vulnerability
Cisco’s Product Security Incident Response Team (PSIRT) stated that it became aware of in-the-wild exploitation in August 2026. The company strongly urges customers to move to fixed software rather than rely on temporary controls.
There are no workarounds that fully address the vulnerability. The issue was discovered during internal security testing and was also reported to Cisco by researcher Valerio Brussani (@val_brux of harmonyguard.cloud).
Not every Cisco firewall deployment is automatically at risk. Devices are vulnerable only when they run an affected ASA or FTD release and have certain features enabled that open SSL listen sockets.
Those configurations include SSL VPN with WebVPN enabled on an interface, IKEv2 Remote Access VPN with client services, and, on FTD only, Zero Trust Network Access when that feature is turned on.
Cisco has confirmed that Cisco Secure Firewall Management Center (FMC) Software is not affected. Administrators can verify exposure by reviewing the running configuration for WebVPN, IKEv2 client-services, or zero-trust enablement, and by checking software versions against Cisco’s Fixed Software guidance.
Cisco has published hot fixes for multiple ASA trains, including releases in the 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24 branches, as well as corresponding FTD hot fixes for 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 lines across supported platforms. Hot fixes are available from the Cisco Software Center.
For ASA hot fixes whose names begin with “89,” Cisco notes that ASDM Release 7.24.1.374 or later is required so the management interface correctly recognizes the new numbering format. Customers who prefer a full release upgrade can use the Cisco Software Checker to identify the earliest fixed release for their platform and build.
From an operational standpoint, defenders should treat internet-facing SSL VPN listeners as the primary attack surface. Priority should go to appliances with remote access VPN or zero-trust features enabled, especially those reachable from untrusted networks.
After patching, teams should validate VPN availability, review device reload history, and monitor for anomalous HTTP traffic aimed at VPN portals. Cisco’s full advisory, including fixed software tables and configuration checks, is published at the Cisco Security Center.
For organizations that depend on Cisco ASA or FTD for secure remote access, CVE-2026-20349 is a clear reminder that perimeter VPN services remain a favored target when unauthenticated DoS bugs surface.
Applying vendor hot fixes or upgraded releases promptly is the only reliable path to closing the exposure while exploitation is already underway.
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access
Cyber Attack News
New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide
Cyber Security Funding
Mindgard Raises $30 Million to Tackle AI’s Fastest-Growing Attack Surface
Cyber Security News
China-linked Hackers Using AI Agents to Attack Taiwan Government Websites
Cyber Security News
Critical Adobe ColdFusion Vulnerabilities Allow Attackers to Execute Arbitrary Code
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?