Cisco ASA and FTD DoS Vulnerability Exploited in the Wild (CVE-2026-20349)

Cisco released a security advisory to address a high-severity vulnerability tracked as CVE-2026-20349. The vulnerability impacts the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Successful exploitation of this vulnerability could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned users about the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog. CISA urges users to patch the flaw before August 14, 2025.

Vulnerability Description

The vulnerability originates from the insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. Upon successful exploitation, an attacker could cause the affected device to reload, resulting in a DoS condition.

Affected and Patched Versions

Cisco Secure Firewall ASA and FTD Software Vulnerable Configurations are listed below:

Cisco Secure Firewall ASA and FTD Software Feature Possible Vulnerable Configuration
IKEv2 Remote Access VPN (with client services) crypto ikev2 enable <interface_name> client-services port <port_numbers>
SSL VPN webvpn enable <interface_name>
Zero Trust Network Access zero-trust enable

Note:

  1. For Cisco Secure FTD Software, remote access VPN features are enabled from Devices > VPN > Remote Access in Cisco Secure Firewall Management Center (FMC) Software or from Remote Access VPN in Cisco Secure Firewall Device Manager (FDM).
  2. This feature is available only in Cisco Secure FTD Software.

Cisco Secure Firewall ASA affected and patched versions:

Cisco Secure Firewall ASA Software Release</h Hot Fix Name
9.16 89.16.4.50
9.18 89.18.4.50
9.20 9.20.4.235
9.22 9.22.3.191
9.23 9.23.1.211
9.24 9.24.1.221

Cisco Secure FTD affected and patched versions:

Cisco Secure FTD Software Release Hot Fix Name
7.0  Cisco_FTD_Hotfix_GC-7.0.9.1-1.sh.REL.tar
Cisco_FTD_SSP_FP1K_Hotfix_GC-7.0.9.1-1.sh.REL.tar
Cisco_FTD_SSP_FP2K_Hotfix_GC-7.0.9.1-1.sh.REL.tar
Cisco_FTD_SSP_Hotfix_GC-7.0.9.1-1.sh.REL.tar 
7.2  Cisco_FTD_Hotfix_HM-7.2.11.1-2.sh.REL.tar
Cisco_FTD_SSP_FP1K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
Cisco_FTD_SSP_FP2K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
Cisco_FTD_SSP_FP3K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
Cisco_FTD_SSP_Hotfix_HM-7.2.11.1-2.sh.REL.tar 
7.4  Cisco_FTD_Hotfix_HK-7.4.7.1-1.sh.REL.tar
Cisco_FTD_SSP_FP1K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
Cisco_FTD_SSP_FP2K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
Cisco_FTD_SSP_FP3K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
Cisco_FTD_SSP_Hotfix_HK-7.4.7.1-1.sh.REL.tar
Cisco_Secure_FW_TD_4200_Hotfix_HK-7.4.7.1-1.sh.REL.tar 
7.6  Cisco_FTD_Hotfix_DD-7.6.4.1-2.sh.REL.tar
Cisco_FTD_SSP_FP1K_Hotfix_DD-7.6.4.1-2.sh.REL.tar
Cisco_FTD_SSP_FP3K_Hotfix_DD-7.6.4.1-2.sh.REL.tar
Cisco_FTD_SSP_Hotfix_DD-7.6.4.1-2.sh.REL.tar
Cisco_Secure_FW_TD_4200_Hotfix_DD-7.6.4.1-2.sh.REL.tar 
7.7  Cisco_FTD_Hotfix_AN-7.7.11.1-2.sh.REL.tar
Cisco_FTD_SSP_FP1K_Hotfix_AN-7.7.11.1-2.sh.REL.tar
Cisco_FTD_SSP_FP3K_Hotfix_AN-7.7.11.1-2.sh.REL.tar
Cisco_FTD_SSP_Hotfix_AN-7.7.11.1-2.sh.REL.tar
Cisco_Secure_FW_TD_1200_Hotfix_AN-7.7.11.1-2.sh.REL.tar
Cisco_Secure_FW_TD_4200_Hotfix_AN-7.7.11.1-2.sh.REL.tar 
10.0  Cisco_FTD_Hotfix_S-10.0.0.1-2.sh.REL.tar
Cisco_FTD_SSP_FP1K_Hotfix_S-10.0.0.1-2.sh.REL.tar
Cisco_FTD_SSP_FP3K_Hotfix_S-10.0.0.1-2.sh.REL.tar
Cisco_FTD_SSP_Hotfix_S-10.0.0.1-2.sh.REL.tar
Cisco_Secure_FW_TD_200_Hotfix_R-10.0.0.1-2.sh.REL.tar
Cisco_Secure_FW_TD_1200_Hotfix_S-10.0.0.1-2.sh.REL.tar
Cisco_Secure_FW_TD_4200_Hotfix_S-10.0.0.1-2.sh.REL.tar
Cisco_Secure_FW_TD_6100_Hotfix_S-10.0.0.1-2.sh.REL.tar 

For more information, please refer to the Cisco Security Advisory (cisco-sa-asaftd-vpn-dos-dzv4mQFF).

Qualys Detection

Qualys customers can scan their devices with QIDs 317873 and 317874 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF