Cisco ASA CVE-2026-20349: exploited, no workaround
One unauthenticated HTTP request reloads a Cisco ASA or FTD firewall. CVE-2026-20349 is in CISA's KEV catalog and exploited in the wild. Hot fixes only.
If your remote workers get in through a Cisco firewall, this is your week's job. CVE-2026-20349 lets an unauthenticated attacker on the internet reload your Cisco Secure Firewall ASA or FTD appliance with a single crafted HTTP request. Cisco confirmed active exploitation, CISA put it in the Known Exploited Vulnerabilities catalog on August 11 with a federal deadline of August 14, and there is no workaround. Hot fixes are the only answer.
What actually happened
The bug is an improper-disposal-of-heap-memory issue — insufficient error checking while processing HTTP requests — in the Remote Access SSL VPN service. CVSS 8.6. Per Help Net Security and BleepingComputer, no authentication and no user interaction are required. Send the request, the device reloads, everyone behind it drops.
Affected trains are broad: ASA 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24, and FTD 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. You are exposed if any of three features are enabled — IKEv2 Remote Access VPN with client services, SSL VPN, or Zero Trust Network Access on FTD. Cisco found it during internal security testing; researcher Valerio Brussani reported it as well. Cisco's PSIRT became aware of exploitation in the wild in August and has published no indicators of compromise, which means you cannot check whether you were hit — only whether you are patched.
CISA added it to KEV alongside two other bugs in its August 11 alert, with the federal remediation deadline set for August 14 under BOD 26-04.
Why this Cisco firewall flaw matters for your business
This one takes you offline, not to court. It's a denial of service, not data theft. That reads as lower severity until you notice what the affected service is: the box that terminates your VPN. A remote team, a branch office, a POS network phoning home — all of it stops when the appliance reloads, and it reloads again the next time the attacker sends the request. There is no ransom note and no negotiation. There is just an outage you can't end without patching.
"Turn the feature off" isn't available. Cisco lists no workarounds. Disabling Remote Access VPN to dodge a VPN bug means disabling remote access, which is the same outage the attacker was going to cause. Apply the hot fix for your train and confirm the running version afterward — not the download, the running version.
Know who owns the appliance. Most small businesses did not buy this firewall themselves; an MSP or a network vendor did, and it may be under a support contract that lapsed. Two questions in writing today: what ASA or FTD version are we running, and when is the hot fix going on. A vendor who can't answer inside a day has told you something.
Have a fallback path. Availability bugs on edge devices are common enough that "how do people work when the VPN is down" deserves a documented answer before you need it.
Key takeaways
- CVE-2026-20349 (CVSS 8.6) lets an unauthenticated remote attacker reload Cisco Secure Firewall ASA and FTD devices with a crafted HTTP request
- Affected: ASA 9.16 / 9.18 / 9.20 / 9.22 / 9.23 / 9.24 and FTD 7.0 / 7.2 / 7.4 / 7.6 / 7.7 / 10.0
- Exposure requires IKEv2 Remote Access VPN with client services, SSL VPN, or ZTNA on FTD to be enabled
- Exploited in the wild; CISA added it to KEV on August 11 with an August 14 federal remediation deadline under BOD 26-04
- Cisco published no workarounds and no indicators of compromise — hot fixes are the only remediation and the only thing you can verify
- Get the running version and the patch date from whoever owns the appliance, in writing
An outage you can't end is a business problem, not an IT problem. We inventory the edge devices your business actually depends on, track their patch state, and write down the fallback so a firewall reload doesn't stop the day. Ask us what your perimeter looks like or see how we build resilient stacks.
Sources: Help Net Security, CISA KEV alert, August 11, 2026.
- #cve-2026-20349
- #cisco-asa
- #vpn
- #patching
- #kev
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
vCenter CVE-2026-59310: exploited in five days
Attackers weaponized the vCenter directory traversal five days after disclosure and planted reverse SSH on 361 hosts across 47 countries. Patch math, revisited.
Read itVals AI raises $40M to be the auditor of AI models
a16z led a $40M round for independent AI evaluation. The useful part for operators isn't the funding — it's that benchmarks decay, and yours should too.
Read it