CVE-2026-20349 – Cisco Secure Firewall ASA Software

CVSS 8.6 IMPORTANT Zero Day – Immediate Deployment

“Active exploitation turns a firewall availability flaw into an immediate risk of remote service disruption.”

CVE-2026-20349 is a High-severity denial-of-service vulnerability affecting the Remote Access SSL VPN service in Cisco Secure Firewall ASA and FTD Software. The CVSS score is 8.6, which is High severity. An unauthenticated remote attacker can send a crafted HTTP request that causes an affected device to reload unexpectedly, disrupting VPN and firewall availability.

The vulnerability is actively exploited, increasing the urgency for affected deployments. Cisco security updates address the insufficient HTTP request error handling that enables the attack.

Key Details

Affected Product
Cisco Adaptive Security Appliance Software
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-244
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.