Cisco ASA and FTD Flaw Actively Exploited for Remote DoS
A critical vulnerability in Cisco's firewall software is being exploited in the wild. Unauthenticated attackers can trigger denial-of-service conditions remotely.
TL;DR
- CVE-2026-20349 affects Cisco ASA and FTD software with a CVSS score of 8.6
- The flaw allows remote DoS attacks without authentication
- Insufficient error handling in HTTP request processing is the root cause
- Organizations should apply patches or implement mitigations immediately
- Active exploitation has been confirmed by Cisco and security researchers
Cisco has issued an urgent security advisory regarding CVE-2026-20349, a high-severity vulnerability affecting its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. With a CVSS score of 8.6, this flaw enables unauthenticated remote attackers to trigger denial-of-service conditions.
The vulnerability stems from inadequate error handling when processing specific HTTP requests. Attackers can exploit this weakness without requiring any prior authentication, making it particularly dangerous for exposed network infrastructure. Cisco has confirmed active exploitation of this bug in real-world environments.
Organizations running affected versions of Cisco ASA or FTD software should prioritize patching or implement immediate mitigations to protect their network perimeters from potential service disruption.
Technical Details
- CVE-2026-20349 is classified as a high-severity issue with a CVSS score of 8.6
- The vulnerability exists due to improper error checking during HTTP request processing
- Attackers can trigger the flaw remotely without authentication credentials
- Successful exploitation results in denial-of-service conditions on affected devices
- No user interaction or privileged access is required for exploitation
Impact and Recommendations
- Active exploitation has been confirmed in the wild by Cisco
- Affected products include Cisco ASA and Firepower Threat Defense (FTD) software
- Successful attacks can cause device reloads or make services inaccessible
- Organizations should immediately review their exposure to affected software versions
- Apply Cisco's available patches or implement recommended workarounds until patches can be deployed
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.