Cisco firewall bug can reload devices remotely
Cisco Secure Firewall devices can be forced to reload remotely, disrupting remote-access VPN service. Cisco says attackers have exploited this flaw in the wild.
- Severity
- HighCVSS 3.1 · 8.6
- Fix
- Fixed in 89.16.4.50, 89.18.4.50, 9.20.4.235 +3Fix recorded on Aug 26, 2026
- Weakness
- CWE-244
- Exploit likelihood
- 2.2% in 30 daysEPSS, higher than 82% of known flaws
- Affects
- Cisco Secure Firewall ASA Software+1 more
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Aug 11, 2026
- Federal fix deadline
- Aug 14, 2026
How it works
- An unauthenticated attacker sends a specially crafted HTTP request to the device's Remote Access SSL VPN service.
- The device handles that request incorrectly and reloads unexpectedly.
- This can stop the firewall from providing its VPN service.
What to do
Compare the installed ASA or FTD release with the affected branches and configurations in Cisco's CVE-2026-20349 advisory. Check whether Remote Access VPN, SSL VPN, or FTD Zero Trust Network Access is enabled.
Upgrade ASA to 89.16.4.50, 89.18.4.50, 9.20.4.235, 9.22.3.191, 9.23.1.211, or 9.24.1.221, matching your release branch. For FTD, install the Cisco hotfix for your branch: 7.0.9.1, 7.2.11.1, 7.4.7.1, 7.6.4.1, 7.7.11.1, or 10.0.0.1. Cisco says no workaround addresses this flaw.
Technical details
Affected software: Cisco Secure Firewall ASA Software, Cisco Secure Firewall FTD Software
The flaw affects HTTP request handling in the Remote Access SSL VPN service. Exploitation requires no login and can cause a vulnerable firewall to reload, creating a denial-of-service condition. Cisco released fixes and reported active exploitation in August 2026.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact None No data disclosure
- Integrity impact None No data tampering
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Open in FIRST.org calculatorReferences
- cve.org · CVERecord vdb entry
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource
- tenable.com · CVE-2026-20349 third party advisory vdb entry
- cvefeed.io · CVE-2026-20349 third party advisory vdb entry
- cwe.mitre.org · 244.html vdb entry
- sec.cloudapps.cisco.com · cisco-sa-asaftd-vpn-dos-dzv4mQFF Cisco PSIRT CCCS Canada
- cveawg.mitre.org · CVE-2026-20349 Observed exploitation
- sec.cloudapps.cisco.com · cisco-sa-asaftd-vpn-dos-dzv4mQFF
- cyber.gc.ca · al26-018-vulnerability-affecting-cisco-asa-secure-firewall-threat-defense-software-remote-access-ssl-vpn-cve-2026-20349 CCCS Canada
- thehackernews.com · cisco-asa-and-ftd-flaw-exploited-in.html CCCS Canada