HomeSecurityCisco ASA and FTD: Active exploitation of CVE-2026-20349 in VPN

Cisco ASA and FTD: Active exploitation of CVE-2026-20349 in VPN

CVE -2026-20349 poses a serious threat to Cisco Secure Firewall ASA and FTD devices , as it allows an unauthenticated remote attacker to cause a reboot via a specially crafted HTTP request. Cisco confirms active exploitation, while failure could disrupt remote VPN connections.

Active CVE-2026-20349 exploit in Cisco ASA FTD

The vulnerability has a CVSS score of 8.6 and affects Remote Access SSL VPN, when certain remote access services are active on the device. According to the report by BleepingComputer, Cisco is aware that the vulnerability is being exploited, but has not released any details about the perpetrators or organizations that have been targeted.

The SecNews technical team points out that this is not a vulnerability that directly leads to code execution or data theft. However, remotely disrupting a firewall could leave corporate networks unprotected or disrupt critical connections for employees and partners.

See also: Cisco warns of vulnerability exploitation in ASA and FTD

CVE-2026-20349 and the active exploit

CVE -2026-20349 is due to inadequate error checking in HTTP request processing. An attacker can send a specially crafted request to the Remote Access SSL VPN service and cause the device to reboot unexpectedly. The result is a denial of service condition, without requiring any user account or action.

The attack is remote and does not require prior authentication when there are active SSL listening ports. This increases the risk for devices that expose the VPN directly to the internet. The NVD listing also states that the vulnerability is on the CISA Known Exploited Vulnerabilities list.

Active exploitation of the vulnerability requires increased vigilance. Cisco has not provided any indicators of compromise for the observed activity. Therefore, the absence of any obvious events should not be considered a sign of security. Administrators should review VPN logs, unexpected reboots, and HTTP requests preceding outages.

VPN attack on Cisco ASA and FTD

Which Cisco configurations are affected?

The active exploit targets Cisco Secure Firewall ASA and Secure Firewall Threat Defense (FTD) when remote access features are enabled. Vulnerable configurations include IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD devices.

The versions that need immediate testing include ASA branches 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24, as well as FTD branches 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Cisco has released hotfixes or interim fixes for these branches, so the exact version should be confirmed in the manufacturer's official bulletin.

The Secure Firewall Management Center (FMC) is not affected by this vulnerability. This does not mean that the devices it manages are safe from any other issues, but it does limit the scope of this campaign. The inventory should include both physical devices and virtual installations.

See also: Cisco FMC Zero-Day: Active Exploit and Critical Vulnerability

Cisco ASA and FTD exposed

Immediate actions for administrators

Active exploitation makes it even more urgent to apply fixes. Cisco says there is no workaround that fully fixes CVE-2026-20349. The recommended action is to upgrade to a patched version or apply the available patch, depending on the software branch and device model. Backups and alternate administrative access are required before any changes are made.

At the same time, active exploitation requires security teams to temporarily limit the exposure of VPN interfaces to known addresses or controlled networks, where operationally feasible. Network segmentation, multi-factor authentication, and log aggregation help identify suspicious activity, but are not a substitute for awareness.

After applying the fix, check for unexpected reboots, VPN configuration changes, and new connections from unusual locations. If there are signs of exploitation, the device should be isolated according to the incident response plan and the credentials used for remote access should be examined.

See also: CISA: Warning about vulnerabilities in Cisco products

Fix CVE-2026-20349 in Cisco firewall

The fact that CVE-2026-20349 makes a high-severity availability vulnerability an immediate business priority. Given the active exploit, organizations using ASA or FTD for remote access should document the affected devices, apply the patch, and verify that VPN services are functioning properly after the change. The SecNews technical team recommends that an unexpected reboot not be treated as an isolated technical event, but as a potential indication of an attempted exploit.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS