Security

Heap-inspection DoS in Cisco ASA and FTD SSL VPN (CVE-2026-20349)

Cisco disclosed CVE-2026-20349: a heap inspection flaw in Remote Access SSL VPN for Secure Firewall ASA and FTD that can reload devices (DoS). Cisco released hotfixes; CISA added it to KEV with a short remediation window.

By AheadWire Research DeskPublished 2026-08-12 · Updated 2026-08-12

What changed

Cisco and CISA added CVE-2026-20349 to public advisories and the Known Exploited Vulnerabilities catalog on 2026-08-11; Cisco published hotfixes for multiple ASA and FTD releases and confirmed active exploitation.

Why it matters

The vulnerability can be triggered remotely without authentication against SSL VPN-related services and causes device reloads (availability impact). Affected firewalls could disrupt network perimeter defense or remote access if exploited.

Who is affected

Devices running vulnerable Cisco Secure Firewall ASA or Secure FTD software releases with Remote Access SSL VPN (or related SSL listen socket configurations such as IKEv2 client services or zero-trust remote access) are affected; whether any specific organizations have been compromised beyond Cisco’s note of active exploitation is not stated. Known ransomware use is listed as unknown.

What to do now

  1. Inventory ASA and FTD instances and map software versions against Cisco’s fixed-hotfix list in the advisory and NVD affected versions.
  2. If running a vulnerable release and the device exposes the Remote Access SSL VPN or listed configurations, schedule and apply the Cisco-provided hotfix or upgrade to a fixed release immediately.
  3. Follow CISA guidance (BOD 26-04) to prioritize updates based on internet exposure and organizational risk; for cloud-managed instances follow applicable BOD 26-04 cloud guidance or discontinue use if mitigations are unavailable.
  4. If you cannot immediately patch, isolate or block access to the Remote Access SSL VPN service (reduce internet exposure) and monitor for device reloads and related anomalies; note Cisco states there are no workarounds that address the vulnerability.
  5. Use Cisco Software Checker or contact Cisco TAC with product serial numbers to identify fixed releases and obtain hotfixes when entitlement is unclear.
  6. Preserve forensic data per CISA’s “Forensics Triage Requirements” if you suspect exploitation and follow internal incident response procedures.

Technical scope and vendor guidance

Cisco describes the root cause as insufficient error checking when processing HTTP requests served by the Remote Access SSL VPN service; successful crafted requests can cause the device to reload, producing a denial-of-service condition (CVSS 3.1 base 8.6, availability impact only).

Cisco published hotfixes for many ASA and FTD release branches (lists of hotfix names are in the advisory) and stated there are no workarounds. Cisco also identified which features/configurations can enable the vulnerable SSL listen sockets (examples: webvpn enable <interface>, crypto ikev2 enable <interface> with client-services port, and zero-trust enable in FTD).

Operational and risk notes from CISA/NVD

CISA added CVE-2026-20349 to the Known Exploited Vulnerabilities catalog on 2026-08-11 and set a remediation due date of 2026-08-14, requiring agencies to follow BOD 26-04 remediation timelines.

NVD/Cisco records enumerate many specific ASA and FTD versions marked affected; NVD’s record also notes Cisco and NVD indicate active exploitation (SSVC: exploitation active, automatable: yes).

Questions and answers

Has Cisco released a fix I can install?

Yes—Cisco published hotfixes and fixed releases for multiple ASA and FTD versions in the advisory; consult the advisory’s fixed-software table and the Cisco Software Checker to identify the appropriate hotfix for your release.

Are there workarounds to avoid immediate exposure?

Cisco states there are no workarounds that address this vulnerability; reducing exposure (e.g., blocking access to the Remote Access SSL VPN ports) is an operational mitigation but is not listed by Cisco as a full workaround.

Is exploit activity confirmed?

Cisco’s advisory and NVD indicate the Cisco PSIRT became aware of active exploitation in August 2026; CISA added the CVE to the KEV catalog the same day.

Primary sources

Evidence note: Sources are Cisco’s advisory and the NVD/CISA records; details beyond those documents (e.g., exploit code, victim lists, or telemetry) are not provided in the sources.