Cisco VPN flaw weaponized in active DoS attacks
A high-severity ASA and FTD vulnerability is being exploited to crash devices remotely; hot fixes are available.
Adversaries are actively hammering a high-severity flaw in Cisco's Secure Firewall products, using it to remotely crash VPN gateways and other edge devices. The company this week disclosed that the vulnerability, tracked as CVE-2026-20349, has been exploited in the wild, forcing administrators to weigh emergency patching against potential service disruption.
Under the hood of CVE-2026-20349
The denial-of-service vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. With a CVSS severity score of 8.6, it is considered high-risk and can be triggered remotely without authentication or user interaction when SSL listen sockets are enabled.
According to Cisco's advisory, the root cause is insufficient error checking while processing HTTP requests. An attacker can exploit this by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit causes the device to reload, resulting in a DoS condition.
Who is exposed
The flaw impacts devices running ASA or FTD software with certain remote access services enabled. Specifically, vulnerable configurations include IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD devices. Cisco notes that Secure Firewall Management Center (FMC) software is not affected.
Given the prevalence of these VPN services in enterprise environments, the potential attack surface is substantial. Administrators running any of the affected services should treat this as a critical exposure.
No workaround, but hot fixes are out
Cisco has released hot fixes for affected ASA releases 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, as well as FTD releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. The company states there are no workarounds, and strongly recommends that customers upgrade to a fixed software release to fully remediate the issue.
Hot fixes are a targeted patch that can be applied without a full upgrade, but they still require a reload of the device to take effect. This means administrators must plan for a maintenance window, even as they weigh the urgency of the active exploitation.
Active exploitation: what we know
Cisco's PSIRT says it became aware of active exploitation of CVE-2026-20349 in August 2026. The company has not shared additional information about the attacks, including who is exploiting the vulnerability or what organizations are being targeted. The advisory also does not provide indicators of compromise associated with the ongoing exploitation.
The vulnerability was discovered during Cisco's internal security testing and independently reported to the company by security researcher Valerio Brussani. The confirmation of active exploitation elevates this from a routine patch to an urgent response.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition."
— Cisco, in its security advisory
Related ClamAV expose
In the same advisory cycle, Cisco disclosed that Secure Endpoint Connector for Windows, Mac, and Linux is vulnerable to ClamAV vulnerabilities with public exploits. However, patches for these are not available yet and will be released later this month.
This second issue adds to the patching burden on security teams, who now have to manage a web of affected products with staggered fix timelines.
Quantified impact
- CVSS severity score of 8.6 for CVE-2026-20349
- Six ASA releases (9.16, 9.18, 9.20, 9.22, 9.23, 9.24) affected
- Six FTD releases (7.0, 7.2, 7.4, 7.6, 7.7, 10.0) affected
- Active exploitation first observed in August 2026
What this means for defenders
The lack of workarounds means that for many organizations, patching is not just recommended but mandatory to stop the DoS attacks. The fact that exploitation is already happening in the wild raises the stakes for those who have not yet applied the hot fixes—every day of exposure is a window for attackers to knock critical security infrastructure offline.
This incident also highlights a broader lesson: even well-managed VPN appliances are not immune to remote, unauthenticated crashes. As edge devices become more complex, the attack surface expands, and the cost of delayed patching can be measured in downtime and lost trust.
Administrators should verify their ASA or FTD versions against the affected lists and plan for an immediate maintenance window to apply the hot fixes. The window between disclosure and exploitation is shrinking, and this case is a reminder that adversaries are quick to weaponize newly revealed flaws.
Sources
- BleepingComputer Original source
Continue Reading
Chrome's anti-abuse layers curb 7B notification spam
Google says Chrome's layered defenses cut unwanted Android notifications by over 7 billion daily in Q1 2026.
DeadLock ransomware fortifies itself with blockchain infrastructure
DeadLock ransomware stores config data on Polygon blockchain, complicating infrastructure takedowns by law enforcement.
Fake Wi-Fi on Delta Flight Draws FBI Scrutiny
Passengers on Delta 591 reportedly spoofed onboard Wi-Fi after DEF CON, prompting an FBI inquiry.