Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Cisco has warned that a high-severity flaw (CVE-2026-20349, CVSS 8.6) in its ASA and FTD firewalls, caused by insufficient error checking in HTTP request processing, is being exploited in the wild to trigger remote denial-of-service attacks.
Cisco warned that a high-severity flaw in its Secure Firewall ASA and FTD Software is being exploited in the wild. Tracked as CVE-2026-20349 (CVSS 8.6), the vulnerability stems from insufficient error checking when processing HTTP requests. An unauthenticated, remote attacker can exploit it to trigger a denial-of-service (DoS) condition. Cisco urged users to patch immediately.