Cisco firewall bug can reload devices remotely

Published August 11, 2026 CVE-2026-20349

Cisco Secure Firewall devices can be forced to reload remotely, disrupting remote-access VPN service. Cisco says attackers have exploited this flaw in the wild.

Severity
HighCVSS 3.1 · 8.6
Fix
Fixed in 89.16.4.50, 89.18.4.50, 9.20.4.235 +3Fix recorded on Aug 26, 2026
Weakness
CWE-244
Exploit likelihood
2.2% in 30 daysEPSS, higher than 82% of known flaws
Affects
Cisco Secure Firewall ASA Software+1 more
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Aug 11, 2026
Federal fix deadline
Aug 14, 2026

How it works

  • An unauthenticated attacker sends a specially crafted HTTP request to the device's Remote Access SSL VPN service.
  • The device handles that request incorrectly and reloads unexpectedly.
  • This can stop the firewall from providing its VPN service.

What to do

Compare the installed ASA or FTD release with the affected branches and configurations in Cisco's CVE-2026-20349 advisory. Check whether Remote Access VPN, SSL VPN, or FTD Zero Trust Network Access is enabled.

Upgrade ASA to 89.16.4.50, 89.18.4.50, 9.20.4.235, 9.22.3.191, 9.23.1.211, or 9.24.1.221, matching your release branch. For FTD, install the Cisco hotfix for your branch: 7.0.9.1, 7.2.11.1, 7.4.7.1, 7.6.4.1, 7.7.11.1, or 10.0.0.1. Cisco says no workaround addresses this flaw.

Technical details

Affected software: Cisco Secure Firewall ASA Software, Cisco Secure Firewall FTD Software

The flaw affects HTTP request handling in the Remote Access SSL VPN service. Exploitation requires no login and can cause a vulnerable firewall to reload, creating a denial-of-service condition. Cisco released fixes and reported active exploitation in August 2026.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact None No data disclosure
  • Integrity impact None No data tampering
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Open in FIRST.org calculator