Cisco firewalls are being crashed through a VPN flaw, and the fix is a full software upgrade

A high-severity bug in Cisco's Secure Firewall ASA and FTD software lets attackers reboot devices remotely with a single crafted web request. Cisco says the attacks started in August.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A firewall interface frozen mid-crash with error messages, surrounded by incoming attack vectors represented as red network pathways converging on the device
Share

Key points

  • Cisco is warning customers that a high-severity flaw in its Secure Firewall ASA and Threat Defense (FTD) software, tracked as CVE-2026-20349, is being actively exploited.
  • The bug scores 8.6 out of 10 and lets an unauthenticated attacker crash a firewall by sending one specially crafted web request to its remote-access VPN service.
  • Cisco's PSIRT team says exploitation began in August 2026, but has not named the attackers or the victims.
  • Hot fixes are out for ASA versions 9.16 through 9.24 and FTD versions 7.0 through 10.0; there's no workaround.
  • A separate flaw in Cisco Secure Endpoint Connector, tied to ClamAV, is still waiting on a patch expected later this month.

Cisco is telling customers to patch its Secure Firewall software now, because attackers are already using a bug in it to knock devices offline.

The flaw sits in two products many companies rely on to police network traffic: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). It's tracked as CVE-2026-20349 and rated 8.6 on the 10-point severity scale.

The attack is embarrassingly simple. If a firewall has the remote-access VPN turned on, the service that lets staff dial in from home, an attacker on the internet can send a booby-trapped web request and the box reboots. That's a denial-of-service: the firewall falls over and stops doing its job until it recovers.

Cisco's own security advisory says the cause is "insufficient error checking while processing HTTP requests". No password is needed, and nothing requires a user to click. The bug affects devices with SSL listen sockets enabled, which covers most popular remote-access setups.

Who is affected?

Any organisation running vulnerable ASA or FTD software with remote-access VPN switched on. Cisco Secure Firewall Management Center, the tool admins use to manage the fleet, is not affected.

Three configurations pull a device into scope: IKEv2 Remote Access VPN with client services, SSL VPN, or Zero Trust Network Access on FTD. If none of those are active, the flaw can't be reached.

What has Cisco released, and when?

Hot fixes are available now for the affected releases. There's no workaround, so an upgrade is the only real option.

Product Affected releases Fix
Cisco Secure Firewall ASA 9.16, 9.18, 9.20, 9.22, 9.23, 9.24 Hot fix available
Cisco Secure Firewall Threat Defense 7.0, 7.2, 7.4, 7.6, 7.7, 10.0 Hot fix available
Cisco Secure Firewall Management Center Not affected None needed

The bug turned up in Cisco's own internal testing and was independently reported by security researcher Valerio Brussani. Cisco's PSIRT spotted real-world exploitation in August 2026 but hasn't said who is behind it or which sectors are being hit. The advisory lists no indicators of compromise, so defenders have no fingerprints to hunt for yet.

This lands two weeks after we reported that Cisco Secure Endpoint Connector carries seven ClamAV vulnerabilities, two with working exploit code already public. Patches for that are still pending.

What should administrators do now?

Patch, and check whether the VPN was actually needed on every device it's enabled on.

Apply the hot fix for your ASA or FTD version this week. If a firewall doesn't need Remote Access SSL VPN, turn it off until the upgrade lands. Watch for unexplained reboots in logs: a crash-loop is the main symptom of active exploitation.

For ordinary staff at affected companies, the visible sign will be dull and familiar: the VPN drops for a few minutes, then returns. That's the firewall rebooting under attack. Report it to IT rather than blaming your home Wi-Fi.

Should you worry?

If your organisation runs Cisco ASA or FTD with remote-access VPN, yes, and urgently. What stands out here isn't the technical complexity, because there isn't any. It's that Cisco's advisory offers defenders nothing to hunt for after the fact. A crash-loop in your logs may be the only signal you get.

© 2026 Threat Vectr