Cisco has disclosed that a high-severity denial-of-service vulnerability affecting Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software is being actively exploited in the wild. The flaw, tracked as CVE-2026-20349, carries a CVSS score of 8.6.

According to Cisco’s advisory, the vulnerability stems from insufficient error checking when processing HTTP requests. An unauthenticated remote attacker can exploit it by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device, causing the device to reload and resulting in a denial-of-service condition.

Affected Configurations

The issue can be triggered remotely without authentication or user interaction whenever SSL listen sockets are enabled. Vulnerable configurations include:

  • IKEv2 Remote Access VPN with client services
  • SSL VPN
  • Zero Trust Network Access on FTD devices

Cisco confirmed that Secure Firewall Management Center (FMC) software is not affected by this vulnerability.

No Workarounds Available

Cisco has released hot fixes for affected ASA versions 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, as well as FTD versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. There are currently no workarounds for the flaw, and Cisco strongly recommends customers upgrade to a fixed software release to fully remediate the issue.

Discovery and Exploitation

Cisco’s Product Security Incident Response Team (PSIRT) said it became aware of active exploitation of CVE-2026-20349 in August 2026, but the company has not disclosed additional details about the attacks, including the identity of the threat actors or which organizations have been targeted. The advisory also does not include indicators of compromise related to the ongoing exploitation.

The vulnerability was identified during Cisco’s internal security testing and was also independently reported to the company by security researcher Valerio Brussani.

This disclosure follows Cisco’s earlier warning this month about ClamAV vulnerabilities affecting Secure Endpoint Connector for Windows, Mac, and Linux, for which patches have not yet been released. Given the active exploitation and lack of mitigations, administrators running Cisco ASA or FTD with remote access VPN services enabled should prioritize applying the available hot fixes as soon as possible.