TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/CISA Orders Federal Agencies to Patch an Actively Exploited Cisco Firewall Flaw by August 14
News

CISA Orders Federal Agencies to Patch an Actively Exploited Cisco Firewall Flaw by August 14

Cisco has patched a firewall zero-day that attackers are already exploiting, and CISA has given federal agencies until August 14 to fix it.

August 12, 2026 3 Min Read
37

Cisco has released hotfixes for a firewall zero-day that attackers are already exploiting, and the U.S. Cybersecurity and Infrastructure Security Agency has given federal civilian agencies until August 14 to apply them. The vulnerability, tracked as CVE-2026-20349, carries a CVSS score of 8.6 and lets an unauthenticated remote attacker crash a Cisco Secure Firewall appliance with a single crafted HTTP request.

Table Of Content

  • Found internally, then caught in the wild
  • A busy year for Cisco firewall bugs

The flaw sits in how Cisco’s Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software process HTTP requests sent to the Remote Access SSL VPN service. In its advisory, published August 11, Cisco said “an attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device,” and that “a successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.” CISA’s Known Exploited Vulnerabilities catalog classifies the underlying issue as a heap inspection vulnerability (CWE-244).

Devices are exposed when Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access is enabled and SSL listen sockets are active: no authentication or user interaction is required to trigger the crash. The affected release trains span ASA versions 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, along with FTD versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Cisco Secure Firewall Management Center (FMC) software is not affected by this particular flaw. There is no workaround; Cisco’s guidance to customers is to upgrade to a fixed release.

Found internally, then caught in the wild

Cisco discovered the bug during its own internal security testing and, as BleepingComputer reported, it was also disclosed independently by security researcher Valerio Brussani. Cisco’s Product Security Incident Response Team says it became aware of active exploitation in August 2026, but it has not disclosed who is behind the attacks, which organizations have been targeted, or any indicators of compromise defenders could check their own logs against.

CISA added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog on August 11 and set a remediation deadline of August 14 under Binding Operational Directive 26-04, “Prioritizing Security Updates Based on Risk.” That directive is binding only on federal civilian executive branch agencies, which now have a three-day window from the catalog addition to apply Cisco’s fix or otherwise mitigate their exposure.

A busy year for Cisco firewall bugs

According to SecurityWeek, CVE-2026-20349 is the twelfth Cisco product vulnerability with a 2026 CVE identifier to land on CISA’s KEV catalog this year. Most of those additions have involved Cisco’s SD-WAN products, though attackers have separately exploited flaws in Unified Communications Manager and Firepower Management Center software elsewhere this year. ASA and FTD appliances typically sit at the network edge, so a device that goes down under a denial-of-service attack does more than inconvenience users behind it: it can knock out the VPN access and traffic inspection an organization depends on until the appliance reloads.

Cisco has not published indicators of compromise, and it says no workaround exists, so organizations running Secure Firewall ASA or FTD with remote-access VPN features enabled need to apply the hotfixes directly rather than treat this as something a configuration change alone can resolve.

Tags:

CISACiscoFirewallNetwork SecurityVulnerability Management

Share

The muddy Fraser River meeting the blue-green Thompson River at their confluence near Lytton, British Columbia
Previous Post

How to Fix Broken Distributed Traces Between Python Microservices With OpenTelemetry

Aerial view of the Pentagon building in Washington, D.C.
Next Post

Palantir’s $244 Million No-Bid Pentagon Deal Turns AI Procurement Into a Conflict-of-Interest Test

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026