Published Wednesday, August 12, 2026 at 10:34 AM PT

BLUF: Unauthenticated remote attackers are actively exploiting a high-severity denial-of-service flaw in Cisco Secure Firewall ASA and FTD. CVSS 8.6. Check inventory immediately for affected versions; patch or isolate if exposed to untrusted networks.
DETAILS
- CVE-2026-20349 in Cisco Secure Firewall ASA and FTD software; CVSS 8.6 (high)
- Attack vector: Unauthenticated remote; no user interaction required
- Exploitation status: Active in the wild; attacks already observed
- Impact: Denial of service against affected firewalls
- Vendor response: Cisco has disclosed and released advisory (patch/workaround status unconfirmed from this report)
IMPACT
Who: Organizations running Cisco ASA or FTD in production, particularly those accessible to untrusted networks.
What: Affected firewalls can be remotely crashed or rendered unavailable, potentially disrupting network security controls and business continuity. ASA/FTD are perimeter devices; DoS here cascades to downstream network access.
Scope: Unknown exact version range; assume all recent versions are at risk until patched.
RECOMMENDED ACTIONS
Immediate (within 24 hours):
- Inventory all Cisco ASA and FTD deployments and their software versions
- Check Cisco Security Advisories for CVE-2026-20349 patch and affected version details
- If exposed to untrusted networks (e.g., internet-facing), deprioritize to internal-only or behind an upstream filter pending patch
Follow-up:
- Apply Cisco patch as soon as tested and available
- Monitor affected appliances for unexpected restarts or high CPU during this window
SOURCES
SOC Prime: CVE-2026-20349 disclosure (CVE details truncated in this report; full Cisco advisory recommended)
CONFIDENCE: Exploitation confirmed by SOC Prime; Cisco disclosure confirmed. Patch availability and full attack vector detail pending vendor advisory review.
Recent high-severity events at publish time:

