Unauthenticated attackers exploit Cisco firewall flaws to cause remote device crashes
Attackers are actively exploiting a high-severity vulnerability in Cisco Secure Firewall ASA and FTD software to remotely crash devices. The flaw allows unauthenticated attackers to trigger unexpected reloads by sending crafted HTTP requests to remote access services. Immediate software upgrades are required as no workarounds exist.
Summary
Cisco has issued an urgent warning regarding a high-severity denial-of-service (DoS) vulnerability, tracked as CVE-2026-20349, that is currently being exploited in the wild. The flaw impacts Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software when certain remote access services are enabled.
The vulnerability allows an unauthenticated, remote attacker to cause the affected device to reload unexpectedly. This results in a complete denial of service for any users relying on those VPN or network access services. Cisco became aware of active exploitation in August 2026, though specific targets and threat actors have not been identified.
What happened
The vulnerability stems from insufficient error checking when the software processes HTTP requests within its Remote Access SSL VPN service. By sending a specifically crafted HTTP request, an attacker can trigger a device reload.
This flaw is particularly critical because it requires no authentication or user interaction to execute. The attack surface includes any configuration where SSL listen sockets are enabled through specific features:
- IKEv2 Remote Access VPN (with client services)
- SSL VPN (webvpn)
- Zero Trust Network Access (on FTD devices)
Cisco confirmed that the Secure Firewall Management Center (FMC) is not affected by this specific vulnerability.
Affected products and fixed versions
The following table outlines the vulnerable software releases and the corresponding hot fixes required to remediate the issue.
Cisco Secure Firewall ASA Hot Fixes
| Release | Hot Fix Name |
|---|---|
| 9.16 | 89.16.4.50 |
| 9.18 | 89.18.4.50 |
| 9.20 | 9.20.4.235 |
| 9.22 | 9.22.3.191 |
| 9.23 | 9.23.1.211 |
| 9.24 | 9.24.1.221 |
Note: For ASA hot fixes starting with '89', users must also install ASDM Release 7.24.1.374.
Cisco Secure FTD Hot Fixes
| Release | Hot Fix Name |
|---|---|
| 7.0 | Cisco_FTD_Hotfix_GC-7.0.9.1-1.sh.REL.tar (and others) |
| 7.2 | Cisco_FTD_Hotfix_HM-7.2.11.1-2.sh.REL.tar (and others) |
| 7.4 | Cisco_FTD_Hotfix_HK-7.4.7.1-1.sh.REL.tar (and others) |
| 7.6 | Cisco_FTD_Hotfix_DD-7.6.4.1-2.sh.REL.tar (and others) |
| 7.7 | Cisco_FTD_Hotfix_AN-7.7.11.1-2.sh.REL.tar (and others) |
| 10.0 | Cisco_FTD_Hotfix_S-10.0.0.1-2.sh.REL.tar (and others) |
Why this matters for defenders
Because the vulnerability can be triggered remotely without credentials, any device exposing SSL VPN or IKEv2 services to the internet is at risk of a sudden crash and reload. This can disrupt entire remote workforces or critical network connectivity.
There are no available workarounds to mitigate this risk; upgrading to the fixed software versions listed above is the only way to prevent exploitation.
Secondary Vulnerability: ClamAV in Secure Endpoint Connector
Separately, Cisco has disclosed that its Secure Endpoint Connector software-running on Windows, Mac, and Linux-is vulnerable to several ClamAV flaws. These vulnerabilities could allow a remote attacker to cause a denial of service by interrupting scanning operations via crafted files (such as zip or GPT files).
The impact is higher on Windows platforms because the ClamAV process runs in a privileged security context there. On Linux and Mac, the impact is considered medium due to lower-privileged execution.
Patches for the Secure Endpoint Connector are expected to be released later in August 2026. Customers using Secure Endpoint Private Cloud should prepare to push these updates once they become available.
Sources
- https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF
