Cisco ASA and FTD DoS Vulnerability Exploited in the Wild (CVE-2026-20349)
Cisco released a security advisory to address a high-severity vulnerability tracked as CVE-2026-20349. The vulnerability impacts the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Successful exploitation of this vulnerability could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned users about the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog. CISA urges users to patch the flaw before August 14, 2025.
Vulnerability Description
The vulnerability originates from the insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. Upon successful exploitation, an attacker could cause the affected device to reload, resulting in a DoS condition.
Affected and Patched Versions
Cisco Secure Firewall ASA and FTD Software Vulnerable Configurations are listed below:
| Cisco Secure Firewall ASA and FTD Software Feature | Possible Vulnerable Configuration |
|---|---|
| IKEv2 Remote Access VPN (with client services) | crypto ikev2 enable <interface_name> client-services port <port_numbers> |
| SSL VPN | webvpn enable <interface_name> |
| Zero Trust Network Access | zero-trust enable |
Note:
- For Cisco Secure FTD Software, remote access VPN features are enabled from Devices > VPN > Remote Access in Cisco Secure Firewall Management Center (FMC) Software or from Remote Access VPN in Cisco Secure Firewall Device Manager (FDM).
- This feature is available only in Cisco Secure FTD Software.
Cisco Secure Firewall ASA affected and patched versions:
| Cisco Secure Firewall ASA Software Release</h | Hot Fix Name |
|---|---|
| 9.16 | 89.16.4.50 |
| 9.18 | 89.18.4.50 |
| 9.20 | 9.20.4.235 |
| 9.22 | 9.22.3.191 |
| 9.23 | 9.23.1.211 |
| 9.24 | 9.24.1.221 |
Cisco Secure FTD affected and patched versions:
| Cisco Secure FTD Software Release | Hot Fix Name |
|---|---|
| 7.0 | Cisco_FTD_Hotfix_GC-7.0.9.1-1.sh.REL.tar Cisco_FTD_SSP_FP1K_Hotfix_GC-7.0.9.1-1.sh.REL.tar Cisco_FTD_SSP_FP2K_Hotfix_GC-7.0.9.1-1.sh.REL.tar Cisco_FTD_SSP_Hotfix_GC-7.0.9.1-1.sh.REL.tar |
| 7.2 | Cisco_FTD_Hotfix_HM-7.2.11.1-2.sh.REL.tar Cisco_FTD_SSP_FP1K_Hotfix_HM-7.2.11.1-2.sh.REL.tar Cisco_FTD_SSP_FP2K_Hotfix_HM-7.2.11.1-2.sh.REL.tar Cisco_FTD_SSP_FP3K_Hotfix_HM-7.2.11.1-2.sh.REL.tar Cisco_FTD_SSP_Hotfix_HM-7.2.11.1-2.sh.REL.tar |
| 7.4 | Cisco_FTD_Hotfix_HK-7.4.7.1-1.sh.REL.tar Cisco_FTD_SSP_FP1K_Hotfix_HK-7.4.7.1-1.sh.REL.tar Cisco_FTD_SSP_FP2K_Hotfix_HK-7.4.7.1-1.sh.REL.tar Cisco_FTD_SSP_FP3K_Hotfix_HK-7.4.7.1-1.sh.REL.tar Cisco_FTD_SSP_Hotfix_HK-7.4.7.1-1.sh.REL.tar Cisco_Secure_FW_TD_4200_Hotfix_HK-7.4.7.1-1.sh.REL.tar |
| 7.6 | Cisco_FTD_Hotfix_DD-7.6.4.1-2.sh.REL.tar Cisco_FTD_SSP_FP1K_Hotfix_DD-7.6.4.1-2.sh.REL.tar Cisco_FTD_SSP_FP3K_Hotfix_DD-7.6.4.1-2.sh.REL.tar Cisco_FTD_SSP_Hotfix_DD-7.6.4.1-2.sh.REL.tar Cisco_Secure_FW_TD_4200_Hotfix_DD-7.6.4.1-2.sh.REL.tar |
| 7.7 | Cisco_FTD_Hotfix_AN-7.7.11.1-2.sh.REL.tar Cisco_FTD_SSP_FP1K_Hotfix_AN-7.7.11.1-2.sh.REL.tar Cisco_FTD_SSP_FP3K_Hotfix_AN-7.7.11.1-2.sh.REL.tar Cisco_FTD_SSP_Hotfix_AN-7.7.11.1-2.sh.REL.tar Cisco_Secure_FW_TD_1200_Hotfix_AN-7.7.11.1-2.sh.REL.tar Cisco_Secure_FW_TD_4200_Hotfix_AN-7.7.11.1-2.sh.REL.tar |
| 10.0 | Cisco_FTD_Hotfix_S-10.0.0.1-2.sh.REL.tar Cisco_FTD_SSP_FP1K_Hotfix_S-10.0.0.1-2.sh.REL.tar Cisco_FTD_SSP_FP3K_Hotfix_S-10.0.0.1-2.sh.REL.tar Cisco_FTD_SSP_Hotfix_S-10.0.0.1-2.sh.REL.tar Cisco_Secure_FW_TD_200_Hotfix_R-10.0.0.1-2.sh.REL.tar Cisco_Secure_FW_TD_1200_Hotfix_S-10.0.0.1-2.sh.REL.tar Cisco_Secure_FW_TD_4200_Hotfix_S-10.0.0.1-2.sh.REL.tar Cisco_Secure_FW_TD_6100_Hotfix_S-10.0.0.1-2.sh.REL.tar |
For more information, please refer to the Cisco Security Advisory (cisco-sa-asaftd-vpn-dos-dzv4mQFF).
Qualys Detection
Qualys customers can scan their devices with QIDs 317873 and 317874 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

Comments are closed.