Cisco has patched a vulnerability in its Secure Firewall products that lets unauthenticated attackers force affected devices to reboot. The flaw is tracked as CVE-2026-20349, also listed as EUVD-2026-56643, carries a CVSS score of 8.6 and affects the remote access SSL VPN service in Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD).
It has been considered actively exploited since 11 August. On the same day, the US agency CISA added it to its KEV catalogue of known exploited vulnerabilities. If you are still weighing up whether a maintenance window is worth it, it is.
One HTTP request is enough
The root cause is insufficient error checking when processing HTTP requests. A remote attacker needs no credentials. They send a specially crafted request to the remote access SSL VPN service, the firewall restarts unexpectedly, and you have a denial of service.
That sounds less severe than code execution, but it is ugly in practice. The device affected is precisely the one your staff use to reach the corporate network. Repeat the attack and the VPN stays down indefinitely, all without a single login.
Who is affected
Cisco ASA versions 9.16.x through 9.24.x and FTD 7.0 through 10.0 are vulnerable, but only where one of the affected configurations is active. According to Cisco's advisory, those are:
- IKEv2 remote access VPN with client services enabled
- SSL VPN, meaning webvpn enabled on an interface
- Zero Trust Network Access
Whether your specific build is affected is quickest to establish through the Cisco Software Checker. Faster than working through the version matrix by hand, given how broad it is.
Applying the hot fixes
Cisco has released hot fixes for every affected version, covering ASA from 9.16.1 to 9.24.1 and FTD from 7.0 to 10.0. The downloads sit in the Cisco Software Center.
There is one trap in the small print. Hot fixes whose names begin with "89" additionally require ASDM release 7.24.1.374. Miss that and you will spend the afternoon wondering why the device no longer manages cleanly.
Putting it in context
No EPSS score has been assigned to this flaw yet. It matters little here, since exploitation is already documented and CISA has acted accordingly. Prioritise affected devices by exposure instead: anything with the SSL VPN service facing the open internet goes first.