CISA Orders Federal Agencies to Patch an Actively Exploited Cisco Firewall Flaw by August 14
Cisco has patched a firewall zero-day that attackers are already exploiting, and CISA has given federal agencies until August 14 to fix it.
Cisco has released hotfixes for a firewall zero-day that attackers are already exploiting, and the U.S. Cybersecurity and Infrastructure Security Agency has given federal civilian agencies until August 14 to apply them. The vulnerability, tracked as CVE-2026-20349, carries a CVSS score of 8.6 and lets an unauthenticated remote attacker crash a Cisco Secure Firewall appliance with a single crafted HTTP request.
The flaw sits in how Cisco’s Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software process HTTP requests sent to the Remote Access SSL VPN service. In its advisory, published August 11, Cisco said “an attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device,” and that “a successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.” CISA’s Known Exploited Vulnerabilities catalog classifies the underlying issue as a heap inspection vulnerability (CWE-244).
Devices are exposed when Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access is enabled and SSL listen sockets are active: no authentication or user interaction is required to trigger the crash. The affected release trains span ASA versions 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, along with FTD versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Cisco Secure Firewall Management Center (FMC) software is not affected by this particular flaw. There is no workaround; Cisco’s guidance to customers is to upgrade to a fixed release.
Found internally, then caught in the wild
Cisco discovered the bug during its own internal security testing and, as BleepingComputer reported, it was also disclosed independently by security researcher Valerio Brussani. Cisco’s Product Security Incident Response Team says it became aware of active exploitation in August 2026, but it has not disclosed who is behind the attacks, which organizations have been targeted, or any indicators of compromise defenders could check their own logs against.
CISA added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog on August 11 and set a remediation deadline of August 14 under Binding Operational Directive 26-04, “Prioritizing Security Updates Based on Risk.” That directive is binding only on federal civilian executive branch agencies, which now have a three-day window from the catalog addition to apply Cisco’s fix or otherwise mitigate their exposure.
A busy year for Cisco firewall bugs
According to SecurityWeek, CVE-2026-20349 is the twelfth Cisco product vulnerability with a 2026 CVE identifier to land on CISA’s KEV catalog this year. Most of those additions have involved Cisco’s SD-WAN products, though attackers have separately exploited flaws in Unified Communications Manager and Firepower Management Center software elsewhere this year. ASA and FTD appliances typically sit at the network edge, so a device that goes down under a denial-of-service attack does more than inconvenience users behind it: it can knock out the VPN access and traffic inspection an organization depends on until the appliance reloads.
Cisco has not published indicators of compromise, and it says no workaround exists, so organizations running Secure Firewall ASA or FTD with remote-access VPN features enabled need to apply the hotfixes directly rather than treat this as something a configuration change alone can resolve.








No Comment! Be the first one.