Cisco firewalls are being crashed through a VPN flaw, and the fix is a full software upgrade
A high-severity bug in Cisco's Secure Firewall ASA and FTD software lets attackers reboot devices remotely with a single crafted web request. Cisco says the attacks started in August.

Key points
- Cisco is warning customers that a high-severity flaw in its Secure Firewall ASA and Threat Defense (FTD) software, tracked as CVE-2026-20349, is being actively exploited.
- The bug scores 8.6 out of 10 and lets an unauthenticated attacker crash a firewall by sending one specially crafted web request to its remote-access VPN service.
- Cisco's PSIRT team says it saw exploitation begin in August 2026, but has not named the attackers or the victims.
- Hot fixes are out for ASA versions 9.16 through 9.24 and FTD versions 7.0 through 10.0; there is no workaround.
- A separate flaw in Cisco Secure Endpoint Connector, tied to ClamAV, is still waiting on a patch expected later this month.
Cisco is telling customers to patch its Secure Firewall software now, because attackers are already using a bug in it to knock the devices offline.
The flaw sits in two products that a lot of companies rely on to police what comes in and out of their networks: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). It is tracked as CVE-2026-20349 and rated 8.6 on the 10-point severity scale.
The attack is embarrassingly simple. If a firewall has the remote-access VPN turned on, meaning the service that lets staff dial in from home, an attacker on the internet can send it a booby-trapped web request and the box reboots. That is a denial-of-service, in plain English: the firewall falls over and stops doing its job until it comes back up.
Cisco's own security advisory says the cause is "insufficient error checking while processing HTTP requests". No password is needed. No user has to click anything. First reported by BleepingComputer, the bug affects devices with SSL listen sockets enabled, which covers most of the popular remote-access setups.
Who is affected?
Any organisation running vulnerable ASA or FTD software with remote-access VPN switched on. Cisco Secure Firewall Management Center, the tool admins use to manage the fleet, is not affected.
Three configurations pull a device into scope: IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD. If none of those are turned on, the flaw cannot be reached.
What has Cisco released, and when?
Hot fixes are available now for the affected releases. There is no workaround, so an upgrade is the only real option.
| Product | Affected releases | Fix |
|---|---|---|
| Cisco Secure Firewall ASA | 9.16, 9.18, 9.20, 9.22, 9.23, 9.24 | Hot fix available |
| Cisco Secure Firewall Threat Defense | 7.0, 7.2, 7.4, 7.6, 7.7, 10.0 | Hot fix available |
| Cisco Secure Firewall Management Center | Not affected | None needed |
The bug turned up in Cisco's own internal testing and was independently reported by security researcher Valerio Brussani. Cisco's Product Security Incident Response Team (PSIRT) says it spotted real-world exploitation in August 2026, but has not said who is behind it or which sectors are being hit. The advisory does not list indicators of compromise, so defenders have no fingerprints to hunt for yet.
What should administrators do now?
Patch, and check whether the VPN was actually needed on every device it is enabled on.
A sensible short list:
- Apply the hot fix for your ASA or FTD version this week, not next quarter.
- If a firewall does not need Remote Access SSL VPN, turn it off until the upgrade lands.
- Watch for unexplained device reboots in logs; a crash-loop is the main symptom of exploitation.
- Keep an eye out for the pending fix to Cisco Secure Endpoint Connector, which is separately vulnerable to ClamAV bugs with public exploit code and is due later this month.
For ordinary staff at affected companies, the visible sign will be dull and familiar: the VPN stops working for a few minutes, then comes back. That is the firewall rebooting under attack. Report it to IT rather than assuming it is a home Wi-Fi glitch.



