SYS::ONLINE
Wasteland.
Briefs1888
Issues23
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-20349 2026-08-11

Cisco ASA/FTD Remote Access SSL VPN Flaw Lands in KEV (CVE-2026-20349)

"CISA added CVE-2026-20349, an unauthenticated, remote denial-of-service bug in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD Software, to the Known Exploited Vulnerabilities catalog on…"

CISA added CVE-2026-20349, an unauthenticated, remote denial-of-service bug in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD Software, to the Known Exploited Vulnerabilities catalog on 2026-08-11, with a federal remediation deadline of 2026-08-14.

What Is It

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software allows an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service condition.

The root cause is insufficient error checking when processing HTTP requests. An attacker exploits it by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device; a successful exploit causes the device to reload. CISA classifies it under CWE-244 and describes it as a heap inspection vulnerability. NVD scores it 8.6 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).

Why It Matters

CISA's addition of this CVE to the KEV catalog confirms active exploitation in the wild. The attack requires no authentication, no user interaction, and low attack complexity, and it reaches the device over the network. The CVSS vector indicates a scope change with high availability impact; reloading a perimeter firewall takes down the VPN concentrator and whatever traffic transits it. Ransomware campaign use is listed as Unknown.

What's Vulnerable

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, where the Remote Access SSL VPN service is in use. The NVD record enumerates a very large affected version list across ASA 9.16.x, 9.18.x, 9.19.x, 9.20.x, 9.22.x, and 9.23.x trains. Consult the Cisco advisory for the authoritative per-version fixed-release mapping. The NVD entry is still marked "Undergoing Analysis" as of 2026-08-11.

Patch Status

CISA's required action: apply mitigations per vendor instructions, in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Due date: 2026-08-14.

Sources