Cisco firewalls are being crashed through a VPN flaw, and the fix is a full software upgrade
A high-severity bug in Cisco's Secure Firewall ASA and FTD software lets attackers reboot devices remotely with a single crafted web request. Cisco says the attacks started in August.

Key points
- Cisco is warning customers that a high-severity flaw in its Secure Firewall ASA and Threat Defense (FTD) software, tracked as CVE-2026-20349, is being actively exploited.
- The bug scores 8.6 out of 10 and lets an unauthenticated attacker crash a firewall by sending one specially crafted web request to its remote-access VPN service.
- Cisco's PSIRT team says exploitation began in August 2026, but has not named the attackers or the victims.
- Hot fixes are out for ASA versions 9.16 through 9.24 and FTD versions 7.0 through 10.0; there's no workaround.
- A separate flaw in Cisco Secure Endpoint Connector, tied to ClamAV, is still waiting on a patch expected later this month.
Cisco is telling customers to patch its Secure Firewall software now, because attackers are already using a bug in it to knock devices offline.
The flaw sits in two products many companies rely on to police network traffic: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). It's tracked as CVE-2026-20349 and rated 8.6 on the 10-point severity scale.
The attack is embarrassingly simple. If a firewall has the remote-access VPN turned on, the service that lets staff dial in from home, an attacker on the internet can send a booby-trapped web request and the box reboots. That's a denial-of-service: the firewall falls over and stops doing its job until it recovers.
Cisco's own security advisory says the cause is "insufficient error checking while processing HTTP requests". No password is needed, and nothing requires a user to click. The bug affects devices with SSL listen sockets enabled, which covers most popular remote-access setups.
Who is affected?
Any organisation running vulnerable ASA or FTD software with remote-access VPN switched on. Cisco Secure Firewall Management Center, the tool admins use to manage the fleet, is not affected.
Three configurations pull a device into scope: IKEv2 Remote Access VPN with client services, SSL VPN, or Zero Trust Network Access on FTD. If none of those are active, the flaw can't be reached.
What has Cisco released, and when?
Hot fixes are available now for the affected releases. There's no workaround, so an upgrade is the only real option.
| Product | Affected releases | Fix |
|---|---|---|
| Cisco Secure Firewall ASA | 9.16, 9.18, 9.20, 9.22, 9.23, 9.24 | Hot fix available |
| Cisco Secure Firewall Threat Defense | 7.0, 7.2, 7.4, 7.6, 7.7, 10.0 | Hot fix available |
| Cisco Secure Firewall Management Center | Not affected | None needed |
The bug turned up in Cisco's own internal testing and was independently reported by security researcher Valerio Brussani. Cisco's PSIRT spotted real-world exploitation in August 2026 but hasn't said who is behind it or which sectors are being hit. The advisory lists no indicators of compromise, so defenders have no fingerprints to hunt for yet.
This lands two weeks after we reported that Cisco Secure Endpoint Connector carries seven ClamAV vulnerabilities, two with working exploit code already public. Patches for that are still pending.
What should administrators do now?
Patch, and check whether the VPN was actually needed on every device it's enabled on.
Apply the hot fix for your ASA or FTD version this week. If a firewall doesn't need Remote Access SSL VPN, turn it off until the upgrade lands. Watch for unexplained reboots in logs: a crash-loop is the main symptom of active exploitation.
For ordinary staff at affected companies, the visible sign will be dull and familiar: the VPN drops for a few minutes, then returns. That's the firewall rebooting under attack. Report it to IT rather than blaming your home Wi-Fi.
Should you worry?
If your organisation runs Cisco ASA or FTD with remote-access VPN, yes, and urgently. What stands out here isn't the technical complexity, because there isn't any. It's that Cisco's advisory offers defenders nothing to hunt for after the fact. A crash-loop in your logs may be the only signal you get.



