Published Wednesday, August 12, 2026 at 10:34 AM PT

ACTIVE EXPLOITATION: Cisco ASA/FTD Remote DoS (CVE-2026-20349)

BLUF: Unauthenticated remote attackers are actively exploiting a high-severity denial-of-service flaw in Cisco Secure Firewall ASA and FTD. CVSS 8.6. Check inventory immediately for affected versions; patch or isolate if exposed to untrusted networks.


DETAILS

  • CVE-2026-20349 in Cisco Secure Firewall ASA and FTD software; CVSS 8.6 (high)
  • Attack vector: Unauthenticated remote; no user interaction required
  • Exploitation status: Active in the wild; attacks already observed
  • Impact: Denial of service against affected firewalls
  • Vendor response: Cisco has disclosed and released advisory (patch/workaround status unconfirmed from this report)

IMPACT

Who: Organizations running Cisco ASA or FTD in production, particularly those accessible to untrusted networks.

What: Affected firewalls can be remotely crashed or rendered unavailable, potentially disrupting network security controls and business continuity. ASA/FTD are perimeter devices; DoS here cascades to downstream network access.

Scope: Unknown exact version range; assume all recent versions are at risk until patched.


Immediate (within 24 hours):

  1. Inventory all Cisco ASA and FTD deployments and their software versions
  2. Check Cisco Security Advisories for CVE-2026-20349 patch and affected version details
  3. If exposed to untrusted networks (e.g., internet-facing), deprioritize to internal-only or behind an upstream filter pending patch

Follow-up:

  • Apply Cisco patch as soon as tested and available
  • Monitor affected appliances for unexpected restarts or high CPU during this window

SOURCES

SOC Prime: CVE-2026-20349 disclosure (CVE details truncated in this report; full Cisco advisory recommended)


CONFIDENCE: Exploitation confirmed by SOC Prime; Cisco disclosure confirmed. Patch availability and full attack vector detail pending vendor advisory review.


Recent high-severity events at publish time:

Recent high-severity events