An unauthenticated attacker can crash any Cisco ASA or FTD with SSL VPN exposed; it’s been confirmed exploited in the wild, and Cisco hasn’t told us who or why.
Attackers Can Force Your Firewall To Reboot
If you run a Cisco Adaptive Security Appliance or a Firepower Threat Defense device with Remote Access SSL VPN enabled, you are exposed to CVE-2026-20349. On August 11, 2026, Cisco published an advisory, scoring the vulnerability as “high” with a CVSS 3.1 score of 8.6. The flaw affects the Remote Access SSL VPN service on most ASA and FTD devices. Cisco describes the vulnerability as “insufficient error checking when processing HTTP requests,” which allows an unauthenticated remote attacker to send a crafted HTTP request and trigger an unexpected device reboot. The entire attack can be executed in one packet and requires no credentials or user interaction. The CVSS vector indicates how easy this vulnerability is to exploit: network-reachable, low complexity, no privileges, no user interaction required. The scope change flag is set because crashing the ASA does not just affect the firewall itself; it cuts off every session the device is managing. No workarounds exist, so patching is the only fix. CISA added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog on August 11, 2026, with a mandatory remediation deadline of August 14, 2026, giving US Federal Civilian Executive Branch agencies just three days to patch. That is how seriously CISA is treating this one.
What Is Affected
The vulnerable configurations are any ASA or FTD instance running one or more of the following: IKEv2 Remote Access VPN with client services, SSL VPN (webvpn), or Zero Trust Network Access (ZTNA) on FTD. If your device serves as a remote access gateway, it is almost certainly one of these.
| Product | Affected Versions |
| Cisco Secure Firewall ASA Software | 9.16, 9.18, 9.20, 9.22, 9.23, 9.24 |
| Cisco Secure Firewall FTD Software | 7.0, 7.2, 7.4, 7.6, 7.7, 10.0 |
Cisco has released hotfixes for all affected release trains. The advisory tables at cisco-sa-asaftd-vpn-dos-dzv4mQFF list the specific patch versions by branch. Cisco identified the flaw through internal testing and researcher Valerio Brussani (@val_brux, harmonyguard.cloud) reported it independently.
What Cisco Is Not Telling Us
This is where I start to get frustrated. Cisco’s PSIRT statement says the team “became aware of active exploitation” in August 2026. That is the complete picture they shared publicly. Cisco has not disclosed the threat actor group, targeted sectors, indicators of compromise, or how many incidents were observed. We don’t have details on what the malicious requests look like or where they originated. CISA’s KEV entry confirms the exploitation is real but adds nothing on attribution or scope. We know exploitation is happening, and almost nothing else. That level of opacity is unusual for a confirmed in-the-wild disclosure at this severity, and it leaves the security community to speculate about the questions that matter for prioritizing response. So let me work through them.
The Questions That Actually Matter
Who is exploiting this?
Right now, we simply do not know. Nation-state actors have operated persistently on Cisco network infrastructure in recent years. Volt Typhoon compromised Cisco ASA devices to establish persistent footholds in US critical infrastructure. Salt Typhoon tunneled through network edge devices for long-term intelligence collection. But the technical bar for CVE-2026-20349 is extremely low, as the attackers do not require authentication, just network access to an SSL VPN listener. This is equally available to opportunistic criminal operators running automated scanning campaigns. Without attribution data from Cisco, we cannot tell which threat actor class is behind the observed exploitation.
Why would someone DoS a firewall?
“Denial of service on a firewall” sounds like a nuisance attack, but forcing an ASA or FTD reboot can help attackers achieve much more nuanced objectives. For example:
- Disruption as the goal. For some attackers, the objective is operational impact in the form of crashing the VPN gateway of a hospital, a utility, or a financial institution at a critical moment. Threat actors can effectively eliminate remote workforce access, drop site-to-site tunnels, and potentially interrupt incident response capabilities. Depending on the target and timing, that can be consequential far beyond a temporary outage.
- Disruption as a precursor. When an ASA or FTD reboots, it clears in-memory state, flushes connection tables, and may leave logging incomplete or absent. An attacker who coordinates a forced reboot with a parallel intrusion gains a disruption window. They can move laterally, establish persistence, and exfiltrate data while detection and response capabilities are reduced. When the firewall comes back up, administrators attribute the reload to an operational issue, and the attacker is already inside.
- Reconnaissance. A device that crashes on a crafted HTTP request confirms to the attacker that the target is running a vulnerable, unpatched version. That information has value for follow-on activity.
- Ransomware disruption tactics. Some ransomware-affiliated groups have shifted toward operational disruption as part of their pressure campaign. They will crash systems and deny access, creating chaos, and using the disruption as leverage without bothering to encrypt anything. A Firewall/VPN gateway DoS fits that playbook.
Who are they targeting?
Cisco has not shared information on sectors or organization types being targeted. The exposed attack surface is enormous by design as SSL VPN endpoints are supposed to be reachable from the Internet. ASA and FTD devices are ubiquitous across enterprise environments, government agencies, healthcare, critical infrastructure, and financial services. Shodan and Censys routinely surface large numbers of Cisco ASA web portals exposed directly to the Internet. The targeting could be sector-specific, and we simply do not have that data, or it could be indiscriminate. Threat actors could scan for VPN endpoints, crash the ones that respond to the crafted HTTP request, noting which ones went offline, and move on.
How widespread is this?
Also unknown. Cisco’s phrasing, “became aware of active exploitation,” could mean a single reported incident, a broad active campaign, or everything in between. CISA’s three-day federal remediation deadline suggests the agency had enough evidence to treat this as a credible and ongoing threat, not a theoretical one. But whether that means a handful of observed incidents or hundreds, I cannot tell you. And apparently neither can Cisco (or they can and have chosen not to).
Why This Matters
The ASA and FTD make access decisions for everything behind them. They handle VPN access for remote employees, connect branch offices to data centers, and in many modern deployments host the Zero Trust Network Access policies that determine who can reach what inside the network. An attacker who can reliably reload these devices on demand has leverage, even if the immediate impact is “just” a temporary outage.
The broader pattern here is familiar to anyone who has watched network edge exploitation evolve over the last several years. Volt Typhoon, Salt Typhoon, the Ivanti wave, and the Fortinet symlink persistence campaigns are all examples that the front door of enterprise networks is the firewall or VPN concentrator; it is directly Internet-exposed by design, and they are vulnerable.
What bothers me about this disclosure is the gap between the action Cisco and CISA are asking for (patch everything in three days) and the threat intelligence they provided to explain why (none). If this were a single incident in a lab environment, it would not make the KEV catalog. But it did make the catalog. The community deserves to know more about what was observed, even if it is a broad-strokes characterization of targeting or a description of the HTTP request pattern that triggers the crash. A list of patched and vulnerable version numbers is not visibility. Patching may mitigate future exploitation of the vulnerability itself. Still, it does not tell you whether an attacker is already living off the land, using stolen session material, or otherwise using the appliance against you in ways that no longer require the vulnerability.
Detection and Mitigation Priorities
It is happening more and more frequently that, like in this incident, the information provided by a vendor’s security advisory, and even from their security and management tooling, is not enough to effectively prioritize a detection and mitigation strategy. In this case, here are my recommendations for how to mitigate your organization’s risk:
- Patch immediately. Apply the hotfix for your specific ASA or FTD release branch from the tables in advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF. There are no workarounds. Treat the CISA deadline of August 14, 2026, for federal agencies as equally urgent for every other organization running this software.
- Check your VPN configuration. Confirm whether your device has IKEv2 Remote Access VPN with client services, SSL VPN (webvpn), or ZTNA enabled. If none are enabled, you are not vulnerable. If any are, patch before anything else.
- Review recent crash logs. If your ASA or FTD has experienced unexpected reloads in August 2026, pull the crash dump and syslog. Look for anomalous HTTP requests to the SSL VPN service in the period immediately preceding each reload. Cisco has not published the exact request signature, but a pattern of crafted requests arriving before a reload is the indicator to hunt.
- Alert on unexpected reloads. Set up alerting for unexpected ASA/FTD device reloads. A pattern of reloads originating from multiple source IPs is a strong indicator of active scanning or exploitation attempts. Your SIEM should correlate reload events with inbound traffic to the SSL VPN service.
- Eclypsium detection. Eclypsium flags Cisco ASA and FTD devices running software versions affected by CVE-2026-20349, giving you immediate visibility into which devices across your network infrastructure are exposed and need to be prioritized for patching. The platform continuously monitors your device inventory so you know when any in-scope device falls behind on a critical patch.

Patching CVE-2026-20349 does not tell you whether an attacker already used this flaw, or a prior one, to stage something inside your perimeter. As in the recent FortiBleed incident or the Fairlife ransomware cyberattack, a patched appliance can still be weaponized, so you need monitoring that goes beyond patch version and detects actual indicators of compromise on network edge devices.
Eclypsium monitors network edge devices from the outside, comparing firmware and configuration against known-good baselines, and detecting the kind of integrity drift that precedes or follows an intrusion.
Frequently Asked Questions
It crashes a Cisco ASA or FTD device. A crafted HTTP request to the Remote Access SSL VPN service causes the device to reload unexpectedly, dropping all active sessions until it recovers.
Any Cisco ASA running 9.16, 9.18, 9.20, 9.22, 9.23, or 9.24, or any FTD running 7.0, 7.2, 7.4, 7.6, 7.7, or 10.0, with SSL VPN, IKEv2 Remote Access VPN with client services, or ZTNA enabled.
No. This is unauthenticated. Network access to the SSL VPN listener is all that is required.
No. Cisco is explicit: there are no workarounds. Patch.
Yes. Cisco PSIRT confirmed active exploitation in August 2026. CISA added it to the Known Exploited Vulnerabilities catalog with a three-day federal remediation deadline.
We do not know. Cisco has provided no attribution, targeting information, or indicators of compromise. For a confirmed-in-the-wild High-severity vulnerability on Internet-exposed network infrastructure, that is a significant gap.
Yes. A forced firewall reload creates a disruption window, clears in-memory state, and can introduce gaps in log coverage. An attacker who coordinates the reload with a parallel intrusion has a meaningful advantage. Patch and then review your crash logs.
Apply the hotfix for your release branch from cisco-sa-asaftd-vpn-dos-dzv4mQFF. Check for unexpected device reloads in August 2026. Review crash logs for anomalous SSL VPN traffic.
Sources
- Cisco Security Advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF
- CISA Known Exploited Vulnerabilities Catalog: CVE-2026-20349
- KEV Intelligence: CVE-2026-20349
- BleepingComputer: Cisco warns of ASA and FTD VPN flaw exploited to crash devices
- Help Net Security: Cisco fixes vulnerability exploited to DoS its firewalls.
- The Hacker News: Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
- SOC Prime: CVE-2026-20349: Cisco ASA and FTD VPN DoS Flaw
