Cisco firewall SSL VPN zero-day exploited

Cisco firewall SSL VPN flaw actively exploited in the wild

SecurityWeek reports that Cisco has warned of active exploitation of CVE-2026-20349, a high-severity vulnerability rated 8.6 on the CVSS scale, affecting its Secure Firewall product line. The issue resides in the Remote Access SSL VPN component of both Cisco Secure Firewall ASA and FTD software.

The flaw originates from inadequate error checking during HTTP request processing. An attacker can trigger a denial-of-service condition by transmitting a specially constructed HTTP request to the VPN service, forcing the appliance to reboot. No authentication or user interaction is required for exploitation.

Cisco's Product Security Incident Response Team confirmed it detected exploitation attempts in the wild and stated that no effective workaround exists — patching is the only remedy.

CISA has added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until August 14 to apply fixes under Binding Operational Directive 26-04. While that deadline applies to government networks, the KEV listing serves as a broader alert for private-sector organizations to prioritize emergency patching. For enterprises relying on ASA and FTD as remote-access gateways, the message is clear: with active exploitation confirmed and no workaround available, the gap between disclosure and mass scanning is expected to be short. This marks the 12th Cisco product CVE from 2026 added to the KEV list this year.

References