AI Weekly Malaysia

Back to items Summaries

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

ID
13393
Status
summarized
Published
12 Aug 2026, 2:15 PM
Fetched
12 Aug 2026, 5:22 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
12 Aug 2026, 5:23 PM
Tags
Audience
developers

What happened

Cisco has confirmed active exploitation of CVE-2026-20349 (CVSS 8.6), a high-severity denial-of-service vulnerability in Secure Firewall ASA and FTD Software. An unauthenticated remote attacker can send a crafted HTTP request to the Remote Access SSL VPN service on affected devices, causing them to reload. The flaw stems from insufficient error checking when processing HTTP requests and affects devices with IKEv2 Remote Access VPN, SSL-VPN, or Zero Trust Network Access enabled across ASA versions 9.16 through 9.24 and FTD versions 7.0 through 7.6.

Why it matters

If your organization runs Cisco ASA or FTD firewalls with SSL VPN, IKEv2 Remote Access VPN, or Zero Trust Network Access enabled, you should patch to the fixed versions listed in the advisory immediately—this is being actively exploited. If you don't manage Cisco firewall appliances directly, this has no actionable impact on your work.

Discussion angle

Brief mention only: ask if anyone in the community manages Cisco ASA/FTD firewalls with SSL VPN exposed to the internet, and move on—this is a niche infrastructure patch, not something most builders ship with.

Top