Security teams managing Cisco’s edge infrastructure are facing an urgent patching requirement following the disclosure of a zero-day vulnerability actively exploited in the wild. Identified as CVE-2026-20349, this flaw affects the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Exploitation of this vulnerability can lead to unexpected device reloads, resulting in denial-of-service (DoS) conditions that disrupt remote access and associated network traffic.
The vulnerability arises from inadequate error handling when the SSL VPN service processes HTTP requests. An unauthenticated remote attacker can exploit this flaw by sending specially crafted HTTP requests to the affected service, causing the device to reload and interrupt VPN sessions and other dependent network services. Given that ASA and FTD devices often serve as network perimeters, even brief outages can significantly impact remote workers, site-to-site connectivity, and critical business applications.
Details of the Vulnerability
Cisco’s Product Security Incident Response Team (PSIRT) became aware of active exploitation of CVE-2026-20349 in August 2026. The company strongly advises customers to apply the available patches promptly, as no workarounds fully mitigate the vulnerability. The issue was identified during internal security testing and was also reported by researcher Valerio Brussani.
Not all Cisco firewall deployments are vulnerable. Devices are at risk only if they run affected ASA or FTD versions and have specific features enabled that open SSL listen sockets. Vulnerable configurations include:
- SSL VPN with WebVPN enabled on an interface
- IKEv2 Remote Access VPN with client services
- Zero Trust Network Access enabled (on FTD devices only)
Cisco Secure Firewall Management Center (FMC) Software is confirmed to be unaffected. Administrators should review their configurations for WebVPN, IKEv2 client services, or zero-trust enablement and verify software versions against Cisco’s guidance to determine exposure.
Mitigation and Recommendations
Cisco has released hotfixes for multiple ASA versions, including releases in the 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24 branches, as well as corresponding FTD hotfixes for versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 across supported platforms. These hotfixes are available through the Cisco Software Center. For ASA hotfixes beginning with “89,” Cisco notes that ASDM Release 7.24.1.374 or later is required to ensure proper recognition of the new numbering format. Customers preferring a full release upgrade can use the Cisco Software Checker to identify the earliest fixed release for their platform.
Organizations should prioritize patching internet-facing SSL VPN listeners, especially appliances with remote access VPN or zero-trust features enabled and accessible from untrusted networks. After applying patches, it is crucial to validate VPN availability, review device reload histories, and monitor for unusual HTTP traffic targeting VPN portals. Cisco’s comprehensive advisory, including fixed software tables and configuration checks, is available at the Cisco Security Center.
For organizations relying on Cisco ASA or FTD for secure remote access, CVE-2026-20349 underscores the importance of promptly addressing vulnerabilities in perimeter VPN services, as they remain prime targets for unauthenticated DoS attacks. Applying vendor-provided hotfixes or upgraded releases without delay is essential to mitigate this actively exploited threat.
Given the critical nature of this vulnerability and its active exploitation, organizations must act swiftly to secure their network perimeters. Delays in patching could lead to significant disruptions in remote access capabilities and overall network security. Continuous monitoring and timely updates are vital in defending against such evolving threats.