Attackers are knocking Cisco firewalls offline by abusing a flaw in the VPN service that many organizations deliberately expose to the internet. Cisco's Product Security Incident Response Team said on August 11 that it had become aware of active exploitation of the bug, which is tracked as CVE-2026-20349.
What's affected
The flaw is in the Remote Access SSL VPN feature of Cisco Secure Firewall ASA Software and Secure Firewall Threat Defense (FTD) Software, and it only matters where that VPN service is switched on. Cisco lists ASA releases 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24, and FTD releases 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. It scores the issue 8.6 out of 10.
How the attack works
An unauthenticated attacker, meaning one who needs no account or credentials, can send crafted HTTP requests to the VPN service and cause the device to reload unexpectedly. Cisco puts the cause down to insufficient error checking when the software processes HTTP requests. The impact is a denial of service: the firewall reboots and remote access goes down with it, which for a device that is often the front door to the corporate network means an outage for every employee working remotely. Cisco has not reported code execution or data theft through this flaw.
What you should do
Cisco has released hot fixes for every affected ASA and FTD train through its Software Center, and states plainly that there are no workarounds. With exploitation already under way and no mitigation short of the fix, internet-facing ASA and FTD appliances running Remote Access SSL VPN belong on an emergency patch schedule rather than the next maintenance window. Where a patch has to wait, unexplained device reloads and repeated VPN outages are the symptom to hunt for in appliance logs.
The advisory landed in a batch of Cisco fixes that Hong Kong's CERT summarized in a bulletin on August 12, covering ten CVEs across Secure Endpoint Connector, ClamAV, Secure Firewall Management Center and Catalyst SD-WAN Manager alongside the ASA and FTD issue. One of those, CVE-2026-20316, is the static credential in Secure Firewall Management Center that CISA flagged as exploited in late July, and Cisco refreshed that advisory on August 11. It caps a heavy stretch for Cisco's firewall and networking lines, which this month also brought critical IOS XE flaws the company turned up in its own internal audit.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.