Network Security - 5 min read - 13 August 2026

Cisco found this firewall flaw being exploited before it had a fix ready. That's the wrong way round.

CVE-2026-20349 lets an unauthenticated attacker knock a Cisco ASA or FTD firewall's VPN service offline with a single crafted HTTP request. Cisco's own incident response team confirmed exploitation was already happening before the 11 August advisory went out - not after a write-up gave attackers a head start, which is how most of these stories usually go.

Most of the vulnerability stories on this site follow a familiar shape: vendor patches quietly, a researcher publishes a technical write-up weeks later, and that write-up is what actually gets attackers moving. CVE-2026-20349 doesn't fit that shape. Cisco's Product Security Incident Response Team disclosed the flaw on 11 August and confirmed, in the same advisory, that it had already observed active exploitation in the wild - which means the window between "this bug exists" and "attackers are using it" had already closed before the public ever heard about either. BleepingComputer's coverage and The Hacker News' write-up both flag the same detail: this is a vendor that found the exploitation itself, not one reacting to somebody else's disclosure.

What actually breaks, and how little it takes

The flaw sits in how Cisco Secure Firewall ASA and FTD software handle HTTP requests sent to the Remote Access SSL VPN service. Insufficient error checking during that processing means a single crafted request, sent by anyone with network access to the VPN endpoint and no credentials at all, can force the device to reload. No authentication, no user interaction, no chained exploit - just a malformed request against a service that, on most enterprise firewalls, sits directly exposed to the internet by design. Cisco rates it 8.6 on CVSS, and the affected footprint is wide: ASA releases 9.16 through 9.24 and FTD releases 7.0 through 10.0, covering effectively every actively supported version still in the field with IKEv2 Remote Access VPN, SSL VPN or Zero Trust Network Access configured.

A denial-of-service bug that still earned a three-day federal deadline

On the surface, a reload-and-recover DoS looks like a lesser problem than the remote code execution flaws that usually drive a KEV addition and a tight deadline on this site - TeamCity's CVE-2026-63077 and LoadMaster's CVE-2026-8037 both earned theirs by handing attackers a shell. CISA added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog on the same day as Cisco's advisory and set a three-day remediation deadline for federal civilian agencies - 14 August - which puts it on the same clock as those RCE bugs despite the lower ceiling on what a successful exploit achieves. That's the right call for a VPN gateway specifically: a firewall that keeps reloading on demand is a firewall an attacker can use to force a failover, mask a second intrusion in the noise of the outage, or simply take a remote-access chokepoint offline at will. Availability of the thing that's supposed to be your perimeter is its own category of risk, not a lesser one just because nothing was exfiltrated.

Fixed, but only if the hotfix is actually applied

Cisco has hotfixes available across every affected ASA and FTD release line, and credits both its own internal security testing and independent researcher Valerio Brussani with finding the issue. There is no workaround - Cisco's guidance is unambiguous that the hotfix is the only remediation, which removes the usual stopgap of disabling a feature or restricting access while a proper patch gets scheduled. That matters because Remote Access SSL VPN is rarely something a network team can simply switch off without breaking remote work for whoever depends on it, which is exactly the kind of operational friction that turns a three-day deadline into a missed one.

  • Identify every ASA (9.16-9.24) and FTD (7.0-10.0) appliance with Remote Access SSL VPN, IKEv2 Remote Access VPN or Zero Trust Network Access enabled, and apply Cisco's hotfix - there is no workaround to fall back on.
  • Treat 14 August as your working deadline even outside the federal estate; Cisco has confirmed exploitation is already active, not theoretical.
  • Check firewall logs for unexplained reloads on VPN-facing appliances going back several weeks - a DoS bug that's been exploitable in the wild before disclosure may already have left a trail.
  • Don't deprioritise a denial-of-service KEV entry against your usual RCE-first patching order; on a perimeter device, forced downtime is itself the attacker's objective, not a side effect.

A firewall that Cisco found being attacked before it had published a fix is not a bug you get to schedule around your normal patch window. If you need help identifying which of your edge devices are exposed and getting hotfixes applied on a compressed timeline, email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources