CVE-2026-20349 – Cisco Secure Firewall ASA Software
CVSS 8.6
IMPORTANT
Zero Day – Immediate Deployment
“Active exploitation turns a firewall availability flaw into an immediate risk of remote service disruption.”
CVE-2026-20349 is a High-severity denial-of-service vulnerability affecting the Remote Access SSL VPN service in Cisco Secure Firewall ASA and FTD Software. The CVSS score is 8.6, which is High severity. An unauthenticated remote attacker can send a crafted HTTP request that causes an affected device to reload unexpectedly, disrupting VPN and firewall availability.
The vulnerability is actively exploited, increasing the urgency for affected deployments. Cisco security updates address the insufficient HTTP request error handling that enables the attack.
Key Details
- Affected Product
- Cisco Adaptive Security Appliance Software
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-244
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.