A critical flaw in Cisco's Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software is being actively exploited, allowing remote attackers to trigger a denial-of-service (DoS) condition. The vulnerability, identified as CVE-2026-20349 with a CVSS score of 8.6, stems from insufficient error checking when processing HTTP requests, enabling unauthenticated attackers to launch the attack. This high-severity flaw can be exploited without requiring any user interaction or authentication, making it a significant concern for organizations relying on these Cisco products. The fact that this vulnerability is being exploited in the wild1 underscores the need for prompt attention and mitigation. So what this means for practitioners is that they should prioritize patching or monitoring their Cisco ASA and FTD deployments to prevent potential disruptions to their network security.
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
⚠️ Critical Alert
Why This Matters
CVE-2026-20349 is in active discussion involving Cisco — exploitation status determines whether this is patch-now or monitor.
References
- The Hacker News. (2026, August 12). Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS. *The Hacker News*. https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html
Original Source
The Hacker News
Read original →